T09 · Insecure Skill Coding Practices
- Location
SKILL.md:684- Finding
Insufficient Validation in Flash Erase and Write Routine
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 684–705
Vulnerability Type: Unsafe memory access and unrestricted Flash modification
Risk Level: Mediumc HAL_StatusTypeDef flash_write(uint32_t addr, uint8_t *data, uint16_t len) { HAL_StatusTypeDef status; uint32_t page_addr = addr & ~(FLASH_PAGE_SIZE - 1); HAL_FLASH_Unlock(); FLASH_EraseInitTypeDef erase; erase.TypeErase = FLASH_TYPEERASE_PAGES; erase.PageAddress = page_addr; erase.NbPages = 1; uint32_t error; status = HAL_FLASHEx_Erase(&erase, &error); if (status != HAL_OK) { HAL_FLASH_Lock(); return status; } for (uint16_t i = 0; i < len; i += 2) { uint16_t half_word = *(uint16_t*)(data + i); status = HAL_FLASH_Program(FLASH_TYPEPROGRAM_HALFWORD, addr + i, half_word); if (status != HAL_OK) break; } HAL_FLASH_Lock(); return status; }Technical Analysis
The example erases and programs Flash without validating that
addrand the entire write range are within an explicitly authorized Flash partition. It also does not verify that the destination address is correctly aligned, that the data fits within the erased page, or that integer arithmetic used to calculate the end address does not overflow.The loop reads two bytes from
dataduring every iteration. Iflenis odd, the final iteration dereferences a 16-bit value when only one valid input byte remains, causing a one-byte out-of-bounds read. Depending on the MCU and alignment requirements, the cast and dereference may also cause an unaligned-access fault.Only the page containing the initial address is erased. A write spanning a page boundary may therefore attempt to program a non-erased page. Conversely, a short partial-page write erases the entire containing page and may destroy unrelated data stored elsewhere in that page.
Attack Path
...[truncated 1613 chars]
- Remediation
View remediation
Remediation Suggestions
- Define an explicit writable Flash partition and reject addresses outside its start and end boundaries.
- Calculate the end address with overflow-safe arithmetic before unlocking Flash.
- Require destination alignment appropriate for
FLASH_TYPEPROGRAM_HALFWORD. - Reject odd lengths or safely construct the final half-word using a defined padding value.
- Verify that the complete write fits within the erased page, or erase every required page after validating the complete range.
- For partial-page updates, read the existing page into a bounded RAM buffer, update the intended bytes, erase the page, and restore the complete page.
- Reject a null
datapointer whenlenis nonzero. - Protect bootloader, option-byte, executable, and security-critical regions with hardware write protection.
- Relock Flash on every exit path and verify the programmed contents before reporting success.
- Use a power-loss-safe format with versioning, checksums, committed-state markers, and redundant slots for persistent configuration.
