Re: [PATCH] xfs: validate attr entry pointer before field access

"Darrick J. Wong" <[email protected]> Tue, 28 Jul 2026 08:12:59 -0700
Newsgroups org.kernel.vger.linux-xfs,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <20260728151259.GM2901224@frogsfrogsfrogs>
On Tue, Jul 28, 2026 at 03:43:40PM +0800, Hongling Zeng wrote:
> xfs_attr3_leaf_verify_entry() accesses lentry/rentry fields (namelen,
> valuelen) before checking if the entry pointer itself is within bounds.
> If nameidx is crafted to point near the end of the buffer, these field
> accesses can read out-of-bounds before the bounds check at
> name_end > buf_end is performed.
> 
> Add explicit bounds checks for entry pointers before accessing their
> fields. Use offsetof() to check that the start of the flexible array
> member (nameval/name) is within bounds, which ensures all preceding
> fields are safe to access.
> 
> Fixes: c84760659dcf2 ("xfs: check attribute leaf block structure")
> Cc: <[email protected]>

Cc: <[email protected]> # v5.5

(for automatic backport)

> Signed-off-by: Hongling Zeng <[email protected]>

Looks correct to me;
Reviewed-by: "Darrick J. Wong" <[email protected]>

--D

> ---
>  fs/xfs/libxfs/xfs_attr_leaf.c | 14 ++++++++++++++
>  1 file changed, 14 insertions(+)
> 
> diff --git a/fs/xfs/libxfs/xfs_attr_leaf.c b/fs/xfs/libxfs/xfs_attr_leaf.c
> index 86c5c09a5db4..b6288395f853 100644
> --- a/fs/xfs/libxfs/xfs_attr_leaf.c
> +++ b/fs/xfs/libxfs/xfs_attr_leaf.c
> @@ -325,6 +325,13 @@ xfs_attr3_leaf_verify_entry(
>  	 */
>  	if (ent->flags & XFS_ATTR_LOCAL) {
>  		lentry = xfs_attr3_leaf_name_local(leaf, idx);
> +
> +		/* Validate lentry pointer is within bounds before field access */
> +		if ((char *)lentry >= buf_end)
> +			return __this_address;
> +		if ((char *)lentry + offsetof(struct xfs_attr_leaf_name_local, nameval) > buf_end)
> +			return __this_address;
> +
>  		namesize = xfs_attr_leaf_entsize_local(lentry->namelen,
>  				be16_to_cpu(lentry->valuelen));
>  		name_end = (char *)lentry + namesize;
> @@ -332,6 +339,13 @@ xfs_attr3_leaf_verify_entry(
>  			return __this_address;
>  	} else {
>  		rentry = xfs_attr3_leaf_name_remote(leaf, idx);
> +
> +		/* Validate rentry pointer is within bounds before field access */
> +		if ((char *)rentry >= buf_end)
> +			return __this_address;
> +		if ((char *)rentry + offsetof(struct xfs_attr_leaf_name_remote, name) > buf_end)
> +			return __this_address;
> +
>  		namesize = xfs_attr_leaf_entsize_remote(rentry->namelen);
>  		name_end = (char *)rentry + namesize;
>  		if (rentry->namelen == 0)
> -- 
> 2.25.1
> 
>