Re: [PATCH] ntfs3: fix out-of-bounds read in decompress_lznt

Konstantin Komarov <[email protected]> Thu, 30 Apr 2026 14:00:36 +0200
Newsgroups dev.linux.lists.ntfs3,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On 4/18/26 15:11, Tristan Madani wrote:

> [You don't often get email from [email protected]. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]
>
> From: Tristan Madani <[email protected]>
>
> decompress_lznt() does not validate array index bounds before accessing
> the decompression table. A corrupted NTFS3 image with invalid compressed
> data can trigger an out-of-bounds read.
>
> Add index bounds checking to prevent the OOB access.
>
> Reported-by: [email protected]
> Cc: [email protected]
> Signed-off-by: Tristan Madani <[email protected]>
> ---
>   fs/ntfs3/lznt.c | 2 +-
>   1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/fs/ntfs3/lznt.c b/fs/ntfs3/lznt.c
> index fdc9b2ebf3410..f818d97850049 100644
> --- a/fs/ntfs3/lznt.c
> +++ b/fs/ntfs3/lznt.c
> @@ -240,7 +240,7 @@ static inline ssize_t decompress_chunk(u8 *unc, u8 *unc_end, const u8 *cmpr,
>                  if (up - unc > LZNT_CHUNK_SIZE)
>                          return -EINVAL;
>                  /* Correct index */
> -               while (unc + s_max_off[index] < up)
> +               while (index < ARRAY_SIZE(s_max_off) - 1 && unc + s_max_off[index] < up)
>                          index += 1;
>
>                  /* Check the current flag for zero. */
> --
> 2.47.3
>
Hello,

Sorry for the delay.
Your patch is applied, thank you.

Regards,
Konstantin