diff options
| author | Michael Brown | 2023-02-13 21:40:42 +0100 |
|---|---|---|
| committer | Michael Brown | 2023-02-14 12:13:45 +0100 |
| commit | 76a286530a8b5bdbab81c3851b851dea2da32114 (patch) | |
| tree | dbdd17ee66f496fa89dbf8ae0854b6031474b9ed /src/include/elf.h | |
| parent | [rng] Check for several functioning RTC interrupts (diff) | |
| download | ipxe-76a286530a8b5bdbab81c3851b851dea2da32114.tar.gz ipxe-76a286530a8b5bdbab81c3851b851dea2da32114.tar.xz ipxe-76a286530a8b5bdbab81c3851b851dea2da32114.zip | |
[image] Check delimiters when parsing command-line key-value arguments
The Linux kernel bzImage image format and the CPIO archive constructor
will parse the image command line for certain arguments of the form
"key=value". This parsing is currently implemented using strstr() in
a way that can cause a false positive suffix match. For example, a
command line containing "highmem=<n>" would erroneously be treated as
containing a value for "mem=<n>".
Fix by centralising the logic used for parsing such arguments, and
including a check that the argument immediately follows a whitespace
delimiter (or is at the start of the string).
Reported-by: Filippo Giunchedi <filippo@esaurito.net>
Signed-off-by: Michael Brown <mcb30@ipxe.org>
Diffstat (limited to 'src/include/elf.h')
0 files changed, 0 insertions, 0 deletions
