Re: [PATCH v2] ntfs: fix off-by-one page overflow in ntfs_decompress()
Namjae Jeon <[email protected]>
| Newsgroups | org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <CAKYAXd-+vL5hePkkb5fbA1ffJAxDQjC-aTovM9ogNyH+TmDykw@mail.gmail.com> |
On Thu, Aug 20, 2026 at 3:33 PM Dennis Tighe <[email protected]> wrote: > > The per-token range check in ntfs_decompress() uses > > if (cb >= cb_sb_end || dp_addr > dp_sb_end) > break; > > so dp_addr == dp_sb_end falls through to the symbol copy > `*dp_addr++ = *cb++`, writing one byte past the destination page. Since > NTFS_SB_SIZE == PAGE_SIZE the destination is a single page, so the byte > lands in the adjacent page, and *dest_ofs is left one past the sub-block > end (the later `*dest_ofs &= ~PAGE_MASK` then yields 1, not 0, so the page > is never finalized and later sub-blocks keep writing further past it). A > corrupted compressed $DATA attribute thus produces a bounded run of > out-of-bounds writes when the file is read. > > Break as soon as dp_addr reaches dp_sb_end; a full sub-block still > completes, as its final copy advances dp_addr to exactly dp_sb_end. > > Fixes: 1e9ea7e04472 ("Revert "fs: Remove NTFS classic"") > Assisted-by: Claude:claude-opus-4-8 > Signed-off-by: Dennis Tighe <[email protected]> > Reviewed-by: Hyunchul Lee <[email protected]> Applied it to #ntfs-next. Thanks!