cmd: upl: fix off-by-one argc check in do_upl_read

do_upl_read() guards against missing arguments with "argc < 1", but
argc always counts argv[0] (the command name) so that condition is
never true. The function then unconditionally dereferences argv[1],
which is out of bounds when the user runs "upl read" with no address
argument and feeds garbage into hextoul()/map_sysmem().

Use "argc < 2" so the address argument is actually required.

Fixes: 264f4b0b34 ("upl: Add a command")
Signed-off-by: Naveen Kumar Chaudhary <naveen.osdev@gmail.com>
This commit is contained in:
Naveen Kumar Chaudhary
2026-07-10 15:52:36 -06:00
committed by Tom Rini
parent b81e716b26
commit bd93d8ea10
+1 -1
View File
@@ -93,7 +93,7 @@ static int do_upl_read(struct cmd_tbl *cmdtp, int flag, int argc,
ulong addr;
int ret;
if (argc < 1)
if (argc < 2)
return CMD_RET_USAGE;
addr = hextoul(argv[1], NULL);