From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Fri, 04 Sep 2026 11:40:06 +0200 Received: from mx1.white.stw.pengutronix.de ([2a0a:edc0:0:b01:1d::107]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x2QOz-00AgAa-1d for lore@lore.pengutronix.de; Fri, 04 Sep 2026 11:40:06 +0200 Authentication-Results: mx1.white.stw.pengutronix.de; dkim=pass header.d=lists.infradead.org header.s=bombadil.20210309 header.b=yB6xBgcO; dmarc=none; spf=pass (mx1.white.stw.pengutronix.de: domain of "barebox-bounces+lore=pengutronix.de@lists.infradead.org" designates 2607:7c80:54:3::133 as permitted sender) smtp.mailfrom="barebox-bounces+lore=pengutronix.de@lists.infradead.org" Received: from bombadil.infradead.org (bombadil.infradead.org [IPv6:2607:7c80:54:3::133]) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPS id 1AF3C201FD7 for ; Fri, 04 Sep 2026 11:40:06 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Transfer-Encoding: Content-Type:MIME-Version:Date:Message-Id:Subject:References:In-Reply-To:To: From:Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=6WNsufuT1/tChyW8DT9OqbMAiHmufN5dGp/U4SiF1R8=; b=yB6xBgcOeB9o5nC1+xpG3Iz6we m54FNC+C8ADnljN18GzaEYf7c/K64EAClovrIEv02KSwh5tWZu4yWPtoP7tosayx5/qxTZpewJy/d ZoUdbFuiSnHGONSl1Z/JpPiXfnq6OBWVyKpWvV04dcDirhVp64so9X8zOeO8lnLCghuVGcaNScvUz 5tzAqEXR7HJvdlOcDlDYpPrz9m8r7lLaZBZtcNIJHgjVKCOGNVQoipDlRkfdeqYz7CZsQSf/cLp00 rurnYnNVEoyKiPXFSm/jfHxQ9gixPmG+0fD23rOvdQ9cyRmRJStWr8655tjSCp3+gFnrSVfkwFjly L0zJuITg==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1x2QO1-00000001Yp5-07qc; Fri, 04 Sep 2026 09:39:05 +0000 Received: from mx1.white.stw.pengutronix.de ([185.203.200.13]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1x2QNz-00000001YoX-0BzI for barebox@lists.infradead.org; Fri, 04 Sep 2026 09:39:04 +0000 Received: from drehscheibe.grey.stw.pengutronix.de (drehscheibe.grey.stw.pengutronix.de [IPv6:2a0a:edc0:0:c01:1d::a2]) (Authenticated sender: relay-from-drehscheibe.grey.stw.pengutronix.de) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPSA id 46591200F53; Fri, 04 Sep 2026 11:39:01 +0200 (CEST) Received: from dude02.red.stw.pengutronix.de ([2a0a:edc0:0:1101:1d::28]) by drehscheibe.grey.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x2QNx-004tZ3-0f; Fri, 04 Sep 2026 11:39:01 +0200 Received: from [::1] (helo=dude02.red.stw.pengutronix.de) by dude02.red.stw.pengutronix.de with esmtp (Exim 4.98.2) (envelope-from ) id 1x2QNx-0000000Fey0-0ahC; Fri, 04 Sep 2026 11:39:01 +0200 From: Sascha Hauer To: barebox@lists.infradead.org, Ahmad Fatoum In-Reply-To: <20260904071621.53334-1-a.fatoum@pengutronix.de> References: <20260904071621.53334-1-a.fatoum@pengutronix.de> Subject: Re: [PATCH] fs: efi: don't leak the file info buffer in efifs_truncate() Message-Id: <178851474113.3732344.14213692068549537042.b4-ty@pengutronix.de> Date: Fri, 04 Sep 2026 11:39:01 +0200 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit X-Mailer: b4 0.14.3 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260904_023903_232273_84AA2EC0 X-CRM114-Status: UNSURE ( 5.21 ) X-CRM114-Notice: Please train this message. X-Spam-Score: -1.9 (-) X-Spam-Report: Spam detection software, running on the system "bombadil.infradead.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: On Fri, 04 Sep 2026 09:16:21 +0200, Ahmad Fatoum wrote: > The 1 KiB EFI_FILE_INFO buffer is never freed on any of the three > exits, and this runs on every truncating open. > > Applied, thanks! [1/1] fs: efi: don't leak the file info buffer in efifs_truncate() https://git.pengutronix.de/cgit/barebox/commit/?id=e55bbfa26b2a (link may not be stable) Content analysis details: (-1.9 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.0 SPF_PASS SPF: sender matches SPF record -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1% [score: 0.0000] 0.0 DMARC_MISSING Missing DMARC policy X-BeenThere: barebox@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "barebox" X-Rspamd-Action: no action X-Rspamd-Server: mx1 X-Stat-Signature: zdtpy34ap88quk175zwzg54gmgnb4u5h X-Rspamd-Queue-Id: 1AF3C201FD7 X-Spamd-Result: default: False [-57.79 / 15.00]; RECEIVED_AUTHENTICATED_BY_MX1(-50.00)[]; BAYES_HAM(-2.98)[99.93%]; DWL_DNSWL_MED(-2.00)[infradead.org:dkim]; KNOWN_LIST_ID(-1.00)[barebox.lists.infradead.org]; RCVD_IN_DNSWL_MED(-0.60)[2a0a:edc0:0:c01:1d::a2:received,2a0a:edc0:0:1101:1d::28:received,2607:7c80:54:3::133:from]; RCVD_DKIM_ARC_DNSWL_MED(-0.50)[]; MAILLIST(-0.20)[mailman]; R_SPF_ALLOW(-0.20)[+mx:c]; R_DKIM_ALLOW(-0.20)[lists.infradead.org:s=bombadil.20210309]; MIME_GOOD(-0.10)[text/plain]; HAS_LIST_UNSUB(-0.01)[]; RECEIVED_HELO_LOCALHOST(0.00)[]; RCPT_COUNT_TWO(0.00)[2]; DMARC_NA(0.00)[pengutronix.de]; MIME_TRACE(0.00)[0:+]; ARC_NA(0.00)[]; RCVD_TLS_LAST(0.00)[]; ASN(0.00)[asn:7247, ipnet:2607:7c80:54::/48, country:US]; DKIM_TRACE(0.00)[lists.infradead.org:+]; RCVD_COUNT_FIVE(0.00)[5]; FROM_NEQ_ENVFROM(0.00)[s.hauer@pengutronix.de,barebox-bounces@lists.infradead.org]; FROM_HAS_DN(0.00)[]; TAGGED_FROM(0.00)[lore=pengutronix.de]; NEURAL_HAM(-0.00)[-1.000]; RCVD_VIA_SMTP_AUTH(0.00)[]; MID_RHS_MATCH_FROM(0.00)[]; TO_DN_SOME(0.00)[]; FORGED_SENDER_MAILLIST(0.00)[] On Fri, 04 Sep 2026 09:16:21 +0200, Ahmad Fatoum wrote: > The 1 KiB EFI_FILE_INFO buffer is never freed on any of the three > exits, and this runs on every truncating open. > > Applied, thanks! [1/1] fs: efi: don't leak the file info buffer in efifs_truncate() https://git.pengutronix.de/cgit/barebox/commit/?id=e55bbfa26b2a (link may not be stable) Best regards, -- Sascha Hauer