Re: [PATCH] ntfs3: fix out-of-bounds read in decompress_lznt
Konstantin Komarov <[email protected]> Thu, 30 Apr 2026 14:00:36 +0200
| Newsgroups | dev.linux.lists.ntfs3,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
On 4/18/26 15:11, Tristan Madani wrote: > [You don't often get email from [email protected]. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ] > > From: Tristan Madani <[email protected]> > > decompress_lznt() does not validate array index bounds before accessing > the decompression table. A corrupted NTFS3 image with invalid compressed > data can trigger an out-of-bounds read. > > Add index bounds checking to prevent the OOB access. > > Reported-by: [email protected] > Cc: [email protected] > Signed-off-by: Tristan Madani <[email protected]> > --- > fs/ntfs3/lznt.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/fs/ntfs3/lznt.c b/fs/ntfs3/lznt.c > index fdc9b2ebf3410..f818d97850049 100644 > --- a/fs/ntfs3/lznt.c > +++ b/fs/ntfs3/lznt.c > @@ -240,7 +240,7 @@ static inline ssize_t decompress_chunk(u8 *unc, u8 *unc_end, const u8 *cmpr, > if (up - unc > LZNT_CHUNK_SIZE) > return -EINVAL; > /* Correct index */ > - while (unc + s_max_off[index] < up) > + while (index < ARRAY_SIZE(s_max_off) - 1 && unc + s_max_off[index] < up) > index += 1; > > /* Check the current flag for zero. */ > -- > 2.47.3 > Hello, Sorry for the delay. Your patch is applied, thank you. Regards, Konstantin