Re: [PATCH] dm-verity: fix buffer overflow in FEC calculation

Sami Tolvanen <[email protected]>
Newsgroups dev.linux.lists.dm-devel
Message-ID <CABCJKue_H1T_v4Mar19JqsM3n7yogLLPPCT_idUXm=k21WnSmQ@mail.gmail.com>
Hi Mikulas,

On Wed, Jul 1, 2026 at 9:14 AM Mikulas Patocka <[email protected]> wrote:
>
> I used Claude to search for bugs in dm-verity and it found this. The bug
> is real, the buffer "lambda" in lib/reed_solomon/decode_rs.c can overflow.
> Claude proposed this fix. I'd like to ask you (as you wrote the dm-verity
> FEC code) to review this patch.
>
> It seems that we can also redice the size of fio->erasures to
> DM_VERITY_FEC_MAX_ROOTS entries.

I agree, this looks valid, and we should also reduce the size of the
array. In addition, it would be nice if decode_rs8 would return an
error when no_eras is too large instead of just quietly overflowing
the buffer.

> if (neras && *neras <= v->fec->roots)
>         fio->erasures[(*neras)++] = i;
>
> This allows *neras to reach roots + 1 (the post-increment pushes it past roots). This
> value is then passed as no_eras to decode_rs8(). Inside the RS decoder
> (lib/reed_solomon/decode_rs.c:113-121), the erasure locator polynomial loop writes
> lambda[j] where j can reach nroots + 1 — one element past the end of lambda[] (which
> is sized nroots + 1, valid indices 0..nroots). The out-of-bounds write lands on
> syn[0], corrupting the syndrome buffer.
>
> Signed-off-by: Mikulas Patocka <[email protected]>
> Assisted-by: Claude:claude-opus-4-6
> Cc: [email protected]
> Fixes: a739ff3f543a ("dm verity: add support for forward error correction")

Looks correct to me.

Reviewed-by: Sami Tolvanen <[email protected]>

Sami
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.