authorAhmad Fatoum <>2021-09-13 10:29:57 +0200
committerSascha Hauer <>2021-10-04 12:46:31 +0200
commitee05dc28e9985640d5df0b46eb6d5bf8ade2cd85 (patch)
blspec: fix use-after-free of firmware search path
firmware_set_searchpath() is used to temporarily extend firmware search path when parsing boot spec files. It does so by first freeing the original firmware pointer and then storing a pointer to a copy of the new search path. firmware_get_searchpath() returns this pointer without copying meaning that following sequence causes a use-after-free: old_fws = firmware_get_searchpath(); firmware_set_searchpath(fws); /* calls free(old_fws) */ firmware_set_searchpath(old_fws); Fix this by keeping around a copy of the search path. Fixes: dfebbb0a5944 ("blspec: Set firmware searchpath") Signed-off-by: Ahmad Fatoum <> Link: Signed-off-by: Sascha Hauer <>
diff --git a/common/firmware.c b/common/firmware.c
--- a/common/firmware.c
+++ b/common/firmware.c
@@ -224,9 +224,9 @@ out:
static char *firmware_path;
-const char *firmware_get_searchpath(void)
+char *firmware_get_searchpath(void)
- return firmware_path;
+ return strdup(firmware_path);
void firmware_set_searchpath(const char *path)