Files
eternalwrt-mt798x/package/utils/fritz-tools/Makefile
T
Hauke Mehrtens 7e7bd602ea fritz-tools: fix out-of-bounds memset in TFFS segment expansion
When growing the segment array in find_entry(), the memset() that zeroes
the newly allocated slots computed the destination with redundant sizeof
scaling:

  memset(segments + (num_segments * sizeof(struct tffs_entry_segment)), ...)

segments is a typed pointer, so pointer arithmetic already scales by the
element size. Multiplying the offset by sizeof again advances the
destination by num_segments * sizeof^2 bytes, landing far outside the
realloc()'d buffer and zeroing unrelated heap memory whenever a TFFS
entry spans multiple segments that require array expansion.

Drop the redundant multiplication so the memset targets segments[num_segments].

This is a robustness fix for malformed/corrupt TFFS content; the parser
only reads the on-device nand-tffs MTD partition as root, so it is not
considered security relevant.

Reported-by: @Vasco0x4
Assisted-by: Claude:claude-opus-4-8
Link: https://github.com/openwrt/openwrt/pull/23763
Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
2026-06-16 00:51:53 +02:00

61 lines
1.5 KiB
Makefile

include $(TOPDIR)/rules.mk
PKG_NAME:=fritz-tools
PKG_RELEASE:=4
CMAKE_INSTALL:=1
include $(INCLUDE_DIR)/package.mk
include $(INCLUDE_DIR)/cmake.mk
define Package/fritz-tools/Default
SECTION:=utils
CATEGORY:=Utilities
endef
define Package/fritz-tffs
$(call Package/fritz-tools/Default)
TITLE:=Utility to partially read the TFFS filesystems
endef
define Package/fritz-tffs/description
Utility to partially read the TFFS filesystems.
endef
define Package/fritz-tffs-nand
$(call Package/fritz-tools/Default)
TITLE:=Utility to partially read the TFFS filesystems on NAND flash
endef
define Package/fritz-tffs-nand/description
Utility to partially read the TFFS filesystems on NAND flash.
endef
define Package/fritz-caldata
$(call Package/fritz-tools/Default)
DEPENDS:=+zlib
TITLE:=Utility to extract WLAN calibration data
endef
define Package/fritz-caldata/description
Utility to extract the zlib compress calibration data from flash.
endef
define Package/fritz-tffs/install
$(INSTALL_DIR) $(1)/usr/bin
$(INSTALL_BIN) $(PKG_BUILD_DIR)/fritz_tffs_read $(1)/usr/bin/fritz_tffs
endef
define Package/fritz-tffs-nand/install
$(INSTALL_DIR) $(1)/usr/bin
$(INSTALL_BIN) $(PKG_BUILD_DIR)/fritz_tffs_nand_read $(1)/usr/bin/fritz_tffs_nand
endef
define Package/fritz-caldata/install
$(INSTALL_DIR) $(1)/usr/bin
$(INSTALL_BIN) $(PKG_BUILD_DIR)/fritz_cal_extract $(1)/usr/bin/
endef
$(eval $(call BuildPackage,fritz-tffs))
$(eval $(call BuildPackage,fritz-tffs-nand))
$(eval $(call BuildPackage,fritz-caldata))