Re: [PATCH] ext4: check dir entry fits before reading the hash trailer in ext4_search_dir()

Andreas Dilger <[email protected]>
Newsgroups org.kernel.vger.linux-ext4,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Jul 9, 2026, at 12:41, Xiang Mei <[email protected]> wrote:
> 
> For casefolded encrypted directories ext4 stores an 8-byte hash trailer
> after the name (EXT4_DIRENT_HASHES()), at an offset derived from
> de->name_len.  On the sb_no_casefold_compat_fallback() path ext4_match()
> reads that trailer, but ext4_search_dir()'s by-hand pre-check only tests
> de->name + de->name_len <= dlimit, which proves the name fits, not the
> rounded trailer.  A crafted entry whose name ends at the block boundary
> passes the check while EXT4_DIRENT_HASHES(de) lands past the block end,
> so ext4_match() reads out of bounds on an ordinary lookup.  KASAN reports
> it as a use-after-free when the page after the directory block holds a
> freed object:
> 
>  BUG: KASAN: use-after-free in ext4_match (fs/ext4/namei.c:1435)
>  Read of size 4 at addr ffff888010458000 by task exploit
>  Call Trace:
>   ext4_match (fs/ext4/namei.c:1435)
>   ext4_search_dir (fs/ext4/namei.c:1470)
>   __ext4_find_entry (fs/ext4/namei.c:1268 fs/ext4/namei.c:1632)
>   ext4_lookup (fs/ext4/namei.c:1703 fs/ext4/namei.c:1769)
>   ...
>   filename_lookup (fs/namei.c:2842)
>   vfs_statx (fs/stat.c:353)
>   __do_sys_newfstatat (fs/stat.c:538)
>   do_syscall_64 (arch/x86/entry/syscall_64.c:94)
>   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
> 
> Require, for hash-in-dirent directories, that the whole entry including
> the rounded trailer fits before calling ext4_match().  This is the same
> bound ext4_check_dir_entry() already enforces via ext4_dir_rec_len(), so
> no well-formed entry is rejected.  The other caller, ext4_find_dest_de(),
> runs ext4_check_dir_entry() first and is unaffected.
> 
> Fixes: 471fbbea7ff7 ("ext4: handle casefolding with encryption")
> Reported-by: Weiming Shi <[email protected]>
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: Xiang Mei <[email protected]>

Reviewed-by: Andreas Dilger <[email protected] <mailto:[email protected]>>

> ---
> fs/ext4/namei.c | 2 ++
> 1 file changed, 2 insertions(+)
> 
> diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c
> index cc49ae04a6f6..3b9740c1c16d 100644
> --- a/fs/ext4/namei.c
> +++ b/fs/ext4/namei.c
> @@ -1467,6 +1467,8 @@ int ext4_search_dir(struct buffer_head *bh, char *search_buf, int buf_size,
>  		/* this code is executed quadratically often */
>  		/* do minimal checking `by hand' */
>  		if (de->name + de->name_len <= dlimit &&
> +		    (!ext4_hash_in_dirent(dir) ||
> +		     (char *)de + ext4_dir_rec_len(de->name_len, dir) <= dlimit) &&
>  		    ext4_match(dir, fname, de)) {
>  			/* found a match - just to be sure, do
>  			 * a full check */
> -- 
> 2.43.0
> 


Cheers, Andreas
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.