[PATCH] ntfs3: fix info-leak in ntfs_rename()
Dmitry Antipov <[email protected]> Tue, 9 Jun 2026 15:36:18 +0300
| Newsgroups | dev.linux.lists.ntfs3 |
|---|---|
| Message-ID | <[email protected]> |
In 'ntfs_rename()', buffer passed to 'fill_name_de()' should be allocated with 'kzalloc()' to avoid exposing contents of an uninitialized kernel memory via 'copy_to_user_iter()'. Reported-by: [email protected] Closes: https://syzkaller.appspot.com/bug?extid=905d785c4923bea2c1db Fixes: ca2a04e84af7 ("ntfs: ->d_compare() must not block") Signed-off-by: Dmitry Antipov <[email protected]> --- fs/ntfs3/namei.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/fs/ntfs3/namei.c b/fs/ntfs3/namei.c index b2af8f695e60..74fe002214f3 100644 --- a/fs/ntfs3/namei.c +++ b/fs/ntfs3/namei.c @@ -303,7 +303,7 @@ static int ntfs_rename(struct mnt_idmap *idmap, struct inode *dir, return err; } - de = kmalloc(PATH_MAX, GFP_KERNEL); + de = kzalloc(PATH_MAX, GFP_KERNEL); if (!de) return -ENOMEM; -- 2.54.0