Re: [PATCH] ntfs: fix off-by-one page overflow in ntfs_decompress()

Hyunchul Lee <[email protected]>
Newsgroups org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-kernel
Message-ID <CANFS6bZyAXG=kphdiq-Lz5+xePW5qvS1SSuGMdoXYvF42f+-sQ@mail.gmail.com>
2026년 8월 18일 (화) 오전 12:18, Dennis Tighe <[email protected]>님이 작성:
>
> The per-token range check in ntfs_decompress() uses
>
>      if (cb >= cb_sb_end || dp_addr > dp_sb_end)
>          break;
>
> so dp_addr == dp_sb_end falls through to the symbol copy
> `*dp_addr++ = *cb++`, writing one byte past the destination page. Since
> NTFS_SB_SIZE == PAGE_SIZE the destination is a single page, so the byte
> lands in the adjacent page, and *dest_ofs is left one past the sub-block
> end (the later `*dest_ofs &= ~PAGE_MASK` then yields 1, not 0, so the page
> is never finalized and later sub-blocks keep writing further past it).  A
> corrupted compressed $DATA attribute then produces a bounded run of
> out-of-bounds writes when the file is read.
>
> The fix is to break as soon as dp_addr reaches dp_sb_end; a full
> sub-block still completes, as its final copy advances dp_addr to exactly
> dp_sb_end.
>
> Fixes: 1e9ea7e04472 ("Revert \"fs: Remove NTFS classic\"")
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: Dennis Tighe <[email protected]>

This patch looks good to me, but I could not
apply this patch:
  warning: Patch sent with format=flowed; space at
    the end of lines might be lost.

Could you send this patch again?

Reviewed-by: Hyunchul Lee <[email protected]>

> ---
> Reproducer is available on request if needed for validation. I was able to
> craft an imagine that would exercise this scenario leading to KASAN UAF
> errors on read-only mounts.
>
>   fs/ntfs/compress.c | 2 +-
>   1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/fs/ntfs/compress.c b/fs/ntfs/compress.c
> index 76bd806b41e..dc5ad951dc6 100644
> --- a/fs/ntfs/compress.c
> +++ b/fs/ntfs/compress.c
> @@ -352,7 +352,7 @@ static int ntfs_decompress(struct page
> *dest_pages[], int completed_pages[],
>           u8 *dp_back_addr;
>
>           /* Check if we are done / still in range. */
> -        if (cb >= cb_sb_end || dp_addr > dp_sb_end)
> +        if (cb >= cb_sb_end || dp_addr >= dp_sb_end)
>               break;
>
>           /* Determine token type and parse appropriately.*/
> --
> 2.47.3
>
>


-- 
Thanks,
Hyunchul
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.