The blk_dread() following the mbr allocation reads one block from the
device. This will lead to overflow if block size is greater than the
size of legacy_mbr. Fix this by allocating at least one block size.

Signed-off-by: Faiz Abbas <faiz_ab...@ti.com>
---
 disk/part_dos.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/disk/part_dos.c b/disk/part_dos.c
index aae9d95906..8ddc13b50c 100644
--- a/disk/part_dos.c
+++ b/disk/part_dos.c
@@ -93,7 +93,8 @@ static int test_block_type(unsigned char *buffer)
 static int part_test_dos(struct blk_desc *dev_desc)
 {
 #ifndef CONFIG_SPL_BUILD
-       ALLOC_CACHE_ALIGN_BUFFER(legacy_mbr, mbr, 1);
+       ALLOC_CACHE_ALIGN_BUFFER(legacy_mbr, mbr,
+                       DIV_ROUND_UP(dev_desc->blksz, sizeof(legacy_mbr)));
 
        if (blk_dread(dev_desc, 0, 1, (ulong *)mbr) != 1)
                return -1;
-- 
2.19.2

_______________________________________________
U-Boot mailing list
U-Boot@lists.denx.de
https://lists.denx.de/listinfo/u-boot

Reply via email to