Re: [PATCH] fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init
Weiming Shi <[email protected]> Wed, 15 Jul 2026 00:48:03 +0800
| Newsgroups | dev.linux.lists.ntfs3,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <CANgPUi2q9JyNDn5PLxEaQ+LKNM_wbtuwNONFw61rZiFEohHO7A@mail.gmail.com> |
Konstantin Komarov <[email protected]> =E4=BA=8E2026=E5=B9=B47=E6=9C=8815=E6=97=A5=E5=91=A8=E4=B8=89 00:45=E5=86= =99=E9=81=93=EF=BC=9A > > On 6/10/26 13:57, Weiming Shi wrote: > > > From: Weiming Wu <[email protected]> > > > > ntfs_reparse_init() and ntfs_objid_init() parse the index root of the > > $Extend/$Reparse and $Extend/$ObjId metafiles (the INDEX_ROOT attribute= s > > named $R and $O). They read its type and rule fields through > > resident_data(), which does not check that the resident attribute is > > large enough to hold them. > > > > mi_enum_attr() accepts a resident attribute with data_off =3D=3D asize = and > > data_size =3D=3D 0. For such an attribute placed last in its MFT record= , > > resident_data() returns a pointer to the end of the record_size buffer, > > so reading root->type / root->rule reads past the allocation. > > > > Use resident_data_ex(attr, sizeof(struct INDEX_ROOT)) and bail out when > > it returns NULL, as ntfs_security_init() already does for $SDH / $SII. > > > > The attribute is only parsed while mounting a crafted image, so this > > needs CAP_SYS_ADMIN. > > > > BUG: KASAN: slab-out-of-bounds in ntfs_reparse_init (fs/ntfs3/fsntfs.= c:2306) > > Read of size 4 at addr ffff88801219dc00 by task mount > > ntfs_reparse_init (fs/ntfs3/fsntfs.c:2306) > > ntfs_fill_super (fs/ntfs3/super.c:1604) > > get_tree_bdev_flags (fs/super.c:1703) > > vfs_get_tree (fs/super.c:1758) > > path_mount (fs/namespace.c:4131) > > __x64_sys_mount (fs/namespace.c:4360) > > > > Fixes: 82cae269cfa9 ("fs/ntfs3: Add initialization of super block") > > Reported-by: Xiang Mei <[email protected]> > > Assisted-by: Claude:claude-opus-4-8 > > Signed-off-by: Weiming Shi <[email protected]> > > --- > > fs/ntfs3/fsntfs.c | 8 ++++---- > > 1 file changed, 4 insertions(+), 4 deletions(-) > > > > diff --git a/fs/ntfs3/fsntfs.c b/fs/ntfs3/fsntfs.c > > index d0434756029b6..42493a2da24ef 100644 > > --- a/fs/ntfs3/fsntfs.c > > +++ b/fs/ntfs3/fsntfs.c > > @@ -2302,8 +2302,8 @@ int ntfs_reparse_init(struct ntfs_sb_info *sbi) > > goto out; > > } > > > > - root_r =3D resident_data(attr); > > - if (root_r->type !=3D ATTR_ZERO || > > + root_r =3D resident_data_ex(attr, sizeof(struct INDEX_ROOT)); > > + if (!root_r || root_r->type !=3D ATTR_ZERO || > > root_r->rule !=3D NTFS_COLLATION_TYPE_UINTS) { > > err =3D -EINVAL; > > goto out; > > @@ -2340,8 +2340,8 @@ int ntfs_objid_init(struct ntfs_sb_info *sbi) > > goto out; > > } > > > > - root =3D resident_data(attr); > > - if (root->type !=3D ATTR_ZERO || > > + root =3D resident_data_ex(attr, sizeof(struct INDEX_ROOT)); > > + if (!root || root->type !=3D ATTR_ZERO || > > root->rule !=3D NTFS_COLLATION_TYPE_UINTS) { > > err =3D -EINVAL; > > goto out; > > -- > > 2.43.0 > > > Hello, > > Very sorry for the delay. > Your patch was applied, thank you. > > Regards, > Konstantin > Hi Konstantin, Thank you for the update and for applying the patch. Best regards, Weiming Shi