mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH ntfs] fs/ntfs3: fix slab-out-of-bounds write in attr_insert_range()
@ 2026-07-09 22:05 Xiang Mei (Microsoft)
  2026-09-28 17:22 ` Konstantin Komarov
  0 siblings, 1 reply; 2+ messages in thread
From: Xiang Mei (Microsoft) @ 2026-07-09 22:05 UTC (permalink / raw)
  To: Konstantin Komarov
  Cc: ntfs3, linux-kernel, AutonomousCodeSecurity, tgopinath, kys,
	Xiang Mei (Microsoft)

When fallocate(FALLOC_FL_INSERT_RANGE) grows a still-resident ntfs3
attribute, attr_insert_range() shifts the inline data using the insert
length 'bytes' as both the destination offset and the copy size:

  memmove(data + bytes, data, bytes);

Both are wrong: the shift must start at the insertion point 'vbo' and
move only the data past it (data_size - vbo). When bytes > data_size the
memmove runs off the end of the data_size + bytes buffer and overflows
the adjacent slab object.

Since vbo < data_size is already enforced above, the reworked offsets stay
within the data_size + bytes buffer and cannot under/overflow.

  BUG: KASAN: slab-out-of-bounds in attr_insert_range (fs/ntfs3/attrib.c:2581)
  Write of size 512 at addr ffff8880135e8b10 by task exploit/142
   ...
   __asan_memmove (mm/kasan/shadow.c:95)
   attr_insert_range (fs/ntfs3/attrib.c:2581)
   ntfs_fallocate (fs/ntfs3/file.c:618)
   vfs_fallocate (fs/open.c:338)
   __x64_sys_fallocate (fs/open.c:362)
   ...

Fixes: 9256ec35359f ("fs/ntfs3: Refactoring attr_insert_range to restore after errors")
Reported-by: AutonomousCodeSecurity@microsoft.com
Signed-off-by: Xiang Mei (Microsoft) <xmei5@asu.edu>
---
 fs/ntfs3/attrib.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/fs/ntfs3/attrib.c b/fs/ntfs3/attrib.c
index c621a4c582f9..a9a2c2104fd6 100644
--- a/fs/ntfs3/attrib.c
+++ b/fs/ntfs3/attrib.c
@@ -2578,8 +2578,8 @@ int attr_insert_range(struct ntfs_inode *ni, u64 vbo, u64 bytes)
 			char *data = Add2Ptr(attr_b,
 					     le16_to_cpu(attr_b->res.data_off));
 
-			memmove(data + bytes, data, bytes);
-			memset(data, 0, bytes);
+			memmove(data + vbo + bytes, data + vbo, data_size - vbo);
+			memset(data + vbo, 0, bytes);
 			goto done;
 		}
 
-- 
2.43.0


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH ntfs] fs/ntfs3: fix slab-out-of-bounds write in attr_insert_range()
  2026-07-09 22:05 [PATCH ntfs] fs/ntfs3: fix slab-out-of-bounds write in attr_insert_range() Xiang Mei (Microsoft)
@ 2026-09-28 17:22 ` Konstantin Komarov
  0 siblings, 0 replies; 2+ messages in thread
From: Konstantin Komarov @ 2026-09-28 17:22 UTC (permalink / raw)
  To: Xiang Mei (Microsoft)
  Cc: ntfs3, linux-kernel, AutonomousCodeSecurity, tgopinath, kys

On 7/10/26 00:05, Xiang Mei (Microsoft) wrote:

> When fallocate(FALLOC_FL_INSERT_RANGE) grows a still-resident ntfs3
> attribute, attr_insert_range() shifts the inline data using the insert
> length 'bytes' as both the destination offset and the copy size:
>
>    memmove(data + bytes, data, bytes);
>
> Both are wrong: the shift must start at the insertion point 'vbo' and
> move only the data past it (data_size - vbo). When bytes > data_size the
> memmove runs off the end of the data_size + bytes buffer and overflows
> the adjacent slab object.
>
> Since vbo < data_size is already enforced above, the reworked offsets stay
> within the data_size + bytes buffer and cannot under/overflow.
>
>    BUG: KASAN: slab-out-of-bounds in attr_insert_range (fs/ntfs3/attrib.c:2581)
>    Write of size 512 at addr ffff8880135e8b10 by task exploit/142
>     ...
>     __asan_memmove (mm/kasan/shadow.c:95)
>     attr_insert_range (fs/ntfs3/attrib.c:2581)
>     ntfs_fallocate (fs/ntfs3/file.c:618)
>     vfs_fallocate (fs/open.c:338)
>     __x64_sys_fallocate (fs/open.c:362)
>     ...
>
> Fixes: 9256ec35359f ("fs/ntfs3: Refactoring attr_insert_range to restore after errors")
> Reported-by: AutonomousCodeSecurity@microsoft.com
> Signed-off-by: Xiang Mei (Microsoft) <xmei5@asu.edu>
> ---
>   fs/ntfs3/attrib.c | 4 ++--
>   1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/fs/ntfs3/attrib.c b/fs/ntfs3/attrib.c
> index c621a4c582f9..a9a2c2104fd6 100644
> --- a/fs/ntfs3/attrib.c
> +++ b/fs/ntfs3/attrib.c
> @@ -2578,8 +2578,8 @@ int attr_insert_range(struct ntfs_inode *ni, u64 vbo, u64 bytes)
>   			char *data = Add2Ptr(attr_b,
>   					     le16_to_cpu(attr_b->res.data_off));
>   
> -			memmove(data + bytes, data, bytes);
> -			memset(data, 0, bytes);
> +			memmove(data + vbo + bytes, data + vbo, data_size - vbo);
> +			memset(data + vbo, 0, bytes);
>   			goto done;
>   		}
>   

Hello,

The patch was applied, thank you.

Regards,
Konstantin


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-28 17:22 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-09 22:05 [PATCH ntfs] fs/ntfs3: fix slab-out-of-bounds write in attr_insert_range() Xiang Mei (Microsoft)
2026-09-28 17:22 ` Konstantin Komarov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®