[PATCH 0/2] squashfs: harden fragment index table sizing

Karl Mehltretter <[email protected]>
Newsgroups org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Two integer overflows undermine fragment index table handling.  One is
in the original fragment sizing macros.  The other is in a bounds check
added by commit 1cac63cc9b2f ("Squashfs: add sanity checks to fragment
reading at mount time").

Patch 1: the fragment byte count wraps on 32-bit, so the index table
is allocated too small and squashfs_frag_lookup() reads out of bounds.
A crafted image triggers a KASAN out-of-bounds read on a 32-bit build.
With the fix the same image fails cleanly at mount.

Patch 2: the check that the table fits before the next one adds two u64
values controlled by the filesystem image and can wrap.

Built W=1 with gcc (x86_64, i386) and clang (x86_64).  Strict
checkpatch is clean.

Karl Mehltretter (2):
  squashfs: fix fragment index table sizing overflow on 32-bit
  squashfs: make the fragment index table bounds check overflow-safe

 fs/squashfs/fragment.c    | 6 ++++--
 fs/squashfs/squashfs_fs.h | 2 +-
 2 files changed, 5 insertions(+), 3 deletions(-)

-- 
2.53.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.