Re: ZDI-CAN-24679: New Vulnerability Report

2024-11-21 Thread Pavel Machek
On Thu 2024-11-14 08:56:36, Tom Rini wrote: > On Thu, Nov 14, 2024 at 04:02:29AM +, zdi-disclosu...@trendmicro.com > wrote: > > > Hi, > > Do you have any updates to share regarding this vulnerability report? > > Michal, microblaze-generic is the most active platform that enables > FS_JFFS2 b

Re: ZDI-CAN-24679: New Vulnerability Report

2024-11-14 Thread Tom Rini
On Thu, Nov 14, 2024 at 03:27:48PM -0800, Tony Dinh wrote: > Hi Tom, > Hi Stefan, > > I've trimmed down the CC list a bit. > > On Thu, Nov 14, 2024 at 12:33 PM Tom Rini wrote: > > > > On Thu, Nov 14, 2024 at 12:18:49PM -0800, Tony Dinh wrote: > > > Hi Tom, > > > Hi Stefan, > > > > > > On Thu, No

Re: ZDI-CAN-24679: New Vulnerability Report

2024-11-14 Thread Tony Dinh
Hi Tom, Hi Stefan, I've trimmed down the CC list a bit. On Thu, Nov 14, 2024 at 12:33 PM Tom Rini wrote: > > On Thu, Nov 14, 2024 at 12:18:49PM -0800, Tony Dinh wrote: > > Hi Tom, > > Hi Stefan, > > > > On Thu, Nov 14, 2024 at 8:33 AM Tom Rini wrote: > > > > > > On Thu, Nov 14, 2024 at 04:07:15

Re: ZDI-CAN-24679: New Vulnerability Report

2024-11-14 Thread Tom Rini
On Thu, Nov 14, 2024 at 12:18:49PM -0800, Tony Dinh wrote: > Hi Tom, > Hi Stefan, > > On Thu, Nov 14, 2024 at 8:33 AM Tom Rini wrote: > > > > On Thu, Nov 14, 2024 at 04:07:15PM +0100, Michal Simek wrote: > > > > > Hi, > > > > > > On 11/14/24 15:56, Tom Rini wrote: > > > > On Thu, Nov 14, 2024 at

Re: ZDI-CAN-24679: New Vulnerability Report

2024-11-14 Thread Tony Dinh
Hi Tom, Hi Stefan, On Thu, Nov 14, 2024 at 8:33 AM Tom Rini wrote: > > On Thu, Nov 14, 2024 at 04:07:15PM +0100, Michal Simek wrote: > > > Hi, > > > > On 11/14/24 15:56, Tom Rini wrote: > > > On Thu, Nov 14, 2024 at 04:02:29AM +, zdi-disclosu...@trendmicro.com > > > wrote: > > > > > > > Hi,

Re: ZDI-CAN-24679: New Vulnerability Report

2024-11-14 Thread Tom Rini
On Thu, Nov 14, 2024 at 05:01:41PM +, Holger Brunck wrote: > Hi Tom, > > > > > > > We have actually discussed this recently and we have other issues with > > > jffs2 and not going to fix it or recommend to use it. > > > JFFS2 should be removed from our configs and it is also not under our > >

RE: ZDI-CAN-24679: New Vulnerability Report

2024-11-14 Thread Holger Brunck
Hi Tom, > > > > We have actually discussed this recently and we have other issues with > > jffs2 and not going to fix it or recommend to use it. > > JFFS2 should be removed from our configs and it is also not under our > regression. > > Ah OK, thanks. Adding a few more maintainers now then. > fo

Re: ZDI-CAN-24679: New Vulnerability Report

2024-11-14 Thread Tom Rini
On Thu, Nov 14, 2024 at 04:07:15PM +0100, Michal Simek wrote: > Hi, > > On 11/14/24 15:56, Tom Rini wrote: > > On Thu, Nov 14, 2024 at 04:02:29AM +, zdi-disclosu...@trendmicro.com > > wrote: > > > > > Hi, > > > Do you have any updates to share regarding this vulnerability report? > > > > M

Re: ZDI-CAN-24679: New Vulnerability Report

2024-11-14 Thread Michal Simek
Hi, On 11/14/24 15:56, Tom Rini wrote: On Thu, Nov 14, 2024 at 04:02:29AM +, zdi-disclosu...@trendmicro.com wrote: Hi, Do you have any updates to share regarding this vulnerability report? Michal, microblaze-generic is the most active platform that enables FS_JFFS2 by default and so vuln

Re: ZDI-CAN-24679: New Vulnerability Report

2024-11-14 Thread Tom Rini
d some resources to look in to fixing this please? Thanks. > > Thanks, > ZDI > > -Original Message- > From: ZDI Disclosures Mailbox > Sent: Thursday, July 18, 2024 4:05 PM > To: 'u-boot@lists.denx.de' ; 'tr...@konsulko.com' > > Subject: ZDI-CAN-2

RE: ZDI-CAN-24679: New Vulnerability Report

2024-11-13 Thread zdi-disclosu...@trendmicro.com
Hi, Do you have any updates to share regarding this vulnerability report? Thanks, ZDI -Original Message- From: ZDI Disclosures Mailbox Sent: Thursday, July 18, 2024 4:05 PM To: 'u-boot@lists.denx.de' ; 'tr...@konsulko.com' Subject: ZDI-CAN-24679: New Vulnerability R

***UNCHECKED*** [zdi-disclosu...@trendmicro.com: ZDI-CAN-24679: New Vulnerability Report]

2024-07-25 Thread Tom Rini
ot;u-boot@lists.denx.de" , "tr...@konsulko.com" Subject: ZDI-CAN-24679: New Vulnerability Report The attachment could not be scanned for viruses because it is a password protected file. ZDI-CAN-24679: Das U-Boot JFFS2 Image Handling Out-Of-Bounds Write Local