[BUG] hpfs: KASAN use-after-free in hpfs_get_ea()

ZW Tang <[email protected]>
Newsgroups gmane.linux.kernel
Message-ID <CAA2SOT6j_6JJVOH3Vu0mDQKX+iebEkHaEhJ_9ofykZLHd98u6Q@mail.gmail.com>
Hi,

I am reporting a KASAN use-after-free issue triggered by a syzkaller
reproducer on Linux 7.2-rc3.

Although a similar HPFS issue appears to have been reported before, I
can still trigger this KASAN use-after-free on Linux 7.2-rc3 with the
attached syzkaller reproducer.

The reproducer mounts a crafted HPFS filesystem image. During mount, HPFS
reports several filesystem errors and then triggers a KASAN use-after-free
in strcmp(), called from hpfs_get_ea(). The crash happens while HPFS is
reading inode metadata during hpfs_fill_super().

This looks like a potential HPFS extended-attribute parsing or lifetime
handling issue when processing a malformed filesystem image. The HPFS code
appears to pass an invalid or already-freed string pointer to strcmp() from
hpfs_get_ea().

Reproducer:
syz reproducer: https://pastebin.com/raw/GRAS4KFk
console output: https://pastebin.com/raw/bnUVVvva
kernel config: https://pastebin.com/raw/nRnxH6Bi

Kernel:
kernel version: 7.2.0-rc3 #1
preemption model: PREEMPT(full)
HEAD commit: 1137d8b5df06137fb49513cc923b3b24d94cb809
environment: QEMU Ubuntu 24.10
taint: Not tainted

Relevant log:

loop0: detected capacity change from 0 to 128

hpfs: filesystem error: invalid number of hotfixes: 2066844986, used:
2066844985; already mounted read-only
hpfs: filesystem error: improperly stopped
hpfs: filesystem error: warning: spare dnodes used, try chkdsk
hpfs: You really don't want any checks? You are crazy...
hpfs: hpfs_map_sector(): read error
hpfs: code page support is disabled

BUG: KASAN: use-after-free in strcmp+0xa7/0xb0
Read of size 1 at addr ffff8880776368a6 by task syz.0.17/10816

CPU: 0 UID: 0 PID: 10816 Comm: syz.0.17 Not tainted 7.2.0-rc3 #1 PREEMPT(full)
Hardware name: QEMU Ubuntu 24.10 PC (i440FX + PIIX, 1996), BIOS
1.16.3-debian-1.16.3-2 04/01/2014

Call Trace:
<TASK>
dump_stack_lvl
print_report
kasan_report
strcmp
hpfs_get_ea
hpfs_read_inode
hpfs_fill_super
get_tree_bdev_flags
vfs_get_tree
fc_mount
path_mount
do_mount
__x64_sys_mount
do_syscall_64
entry_SYSCALL_64_after_hwframe
</TASK>

The syzkaller program uses syz_mount_image$hpfs() with mount options including
err_ro, chkdsk_no, case_asis, and check_none. The crafted image appears to
drive HPFS into the inode / extended-attribute parsing path, where the stale
string pointer is later dereferenced by strcmp().

The system then panics because panic_on_warn is set:

Kernel panic - not syncing: KASAN: panic_on_warn set ...

Thanks
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.