Re: [PATCH] fs/ntfs3: prevent uninitialized lcn caused by zero len

Konstantin Komarov <[email protected]>
Newsgroups dev.linux.lists.ntfs3,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On 2/23/26 09:01, Edward Adam Davis wrote:

> syzbot reported a uninit-value in ntfs_iomap_begin [1].
>
> Since runs was not touched yet, run_lookup_entry() immediately fails
> and returns false, which makes the value of "*len" 0.
> Simultaneously, the new value and err value are also 0, causing the
> logic in attr_data_get_block_locked() to jump directly to ok, ultimately
> resulting in *lcn being triggered before it is set [1].
>
> In ntfs_iomap_begin(), the check for a 0 value in clen is moved forward
> to before updating lcn to avoid this [1].
>
> [1]
> BUG: KMSAN: uninit-value in ntfs_iomap_begin+0x8c0/0x1460 fs/ntfs3/inode.c:825
>   ntfs_iomap_begin+0x8c0/0x1460 fs/ntfs3/inode.c:825
>   iomap_iter+0x9b7/0x1540 fs/iomap/iter.c:110
>
> Local variable lcn created at:
>   ntfs_iomap_begin+0x15d/0x1460 fs/ntfs3/inode.c:786
>
> Fixes: 10d7c95af043 ("fs/ntfs3: add delayed-allocation (delalloc) support")
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=7be88937363ac7ab7bb0
> Tested-by: [email protected]
> Signed-off-by: Edward Adam Davis <[email protected]>
> ---
>   fs/ntfs3/inode.c | 10 +++++-----
>   1 file changed, 5 insertions(+), 5 deletions(-)
>
> diff --git a/fs/ntfs3/inode.c b/fs/ntfs3/inode.c
> index 6e65066ebcc1..eac421cf98a8 100644
> --- a/fs/ntfs3/inode.c
> +++ b/fs/ntfs3/inode.c
> @@ -822,6 +822,11 @@ static int ntfs_iomap_begin(struct inode *inode, loff_t offset, loff_t length,
>   		return err;
>   	}
>   
> +	if (!clen) {
> +		/* broken file? */
> +		return -EINVAL;
> +	}
> +
>   	if (lcn == EOF_LCN) {
>   		/* request out of file. */
>   		if (flags & IOMAP_REPORT) {
> @@ -855,11 +860,6 @@ static int ntfs_iomap_begin(struct inode *inode, loff_t offset, loff_t length,
>   		return 0;
>   	}
>   
> -	if (!clen) {
> -		/* broken file? */
> -		return -EINVAL;
> -	}
> -
>   	iomap->bdev = inode->i_sb->s_bdev;
>   	iomap->offset = offset;
>   	iomap->length = ((loff_t)clen << cluster_bits) - off;

Hello,

Your patch is applied. Thanks.

Regards,
Konstantin
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.