Re: [PATCH] ufs: reject malformed cylinder summary geometry

Ali Ahmet Memis <[email protected]>
Newsgroups gmane.linux.kernel,gmane.linux.file-systems
Message-ID <[email protected]>
I confirmed the overflow this patch closes. ufs_read_cylinder_structures()
in fs/ufs/super.c derives blks from (s_cssize + s_fsize - 1) >> s_fshift and
then copies a full s_fsize bytes per iteration into a kmalloc(s_cssize)
buffer, so once s_fshift is inconsistent with s_fsize, or s_cssize is not a
fragment multiple, the loop writes past the allocation.

The two new checks cover both cases. Requiring s_fshift to equal
ilog2(s_fsize) keeps the shift that produces blks correct, and requiring
s_cssize to equal s_ncg times sizeof(struct ufs_csum) rounded up to a
fragment ties the buffer to the real cylinder group count and makes it a
fragment multiple, so blks times s_fsize equals s_cssize and the copy stays
in bounds. struct ufs_csum is four 32 bit fields for both ufs1 and ufs2, and
this expected size matches the fragroundup(ncg times sizeof(csum)) sizing
that newfs writes.

s_ncg, s_fshift and s_fsize are all assigned earlier in ufs_fill_super(),
before this check runs, so the validation uses initialised values.

Reviewed-by: Ali Ahmet Memis <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.