mirror of https://github.com/wolfSSL/wolfBoot.git
main() loaded a file of any size and parsed it as a manifest: header fields (size, TLVs) were read past the end of the heap allocation, and a header claiming a larger fw_size drove the image hash over an unbounded range. Reject files smaller than IMAGE_HEADER_SIZE before parsing and clamp fw_size to the bytes actually loaded. |
||
|---|---|---|
| .. | ||
| docker/renesas-rx | ||
| workflows | ||