* [PATCH ntfs] fs/ntfs3: fix slab-out-of-bounds write in attr_insert_range()
@ 2026-07-09 22:05 Xiang Mei (Microsoft)
2026-09-28 17:22 ` Konstantin Komarov
0 siblings, 1 reply; 2+ messages in thread
From: Xiang Mei (Microsoft) @ 2026-07-09 22:05 UTC (permalink / raw)
To: Konstantin Komarov
Cc: ntfs3, linux-kernel, AutonomousCodeSecurity, tgopinath, kys,
Xiang Mei (Microsoft)
When fallocate(FALLOC_FL_INSERT_RANGE) grows a still-resident ntfs3
attribute, attr_insert_range() shifts the inline data using the insert
length 'bytes' as both the destination offset and the copy size:
memmove(data + bytes, data, bytes);
Both are wrong: the shift must start at the insertion point 'vbo' and
move only the data past it (data_size - vbo). When bytes > data_size the
memmove runs off the end of the data_size + bytes buffer and overflows
the adjacent slab object.
Since vbo < data_size is already enforced above, the reworked offsets stay
within the data_size + bytes buffer and cannot under/overflow.
BUG: KASAN: slab-out-of-bounds in attr_insert_range (fs/ntfs3/attrib.c:2581)
Write of size 512 at addr ffff8880135e8b10 by task exploit/142
...
__asan_memmove (mm/kasan/shadow.c:95)
attr_insert_range (fs/ntfs3/attrib.c:2581)
ntfs_fallocate (fs/ntfs3/file.c:618)
vfs_fallocate (fs/open.c:338)
__x64_sys_fallocate (fs/open.c:362)
...
Fixes: 9256ec35359f ("fs/ntfs3: Refactoring attr_insert_range to restore after errors")
Reported-by: AutonomousCodeSecurity@microsoft.com
Signed-off-by: Xiang Mei (Microsoft) <xmei5@asu.edu>
---
fs/ntfs3/attrib.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/fs/ntfs3/attrib.c b/fs/ntfs3/attrib.c
index c621a4c582f9..a9a2c2104fd6 100644
--- a/fs/ntfs3/attrib.c
+++ b/fs/ntfs3/attrib.c
@@ -2578,8 +2578,8 @@ int attr_insert_range(struct ntfs_inode *ni, u64 vbo, u64 bytes)
char *data = Add2Ptr(attr_b,
le16_to_cpu(attr_b->res.data_off));
- memmove(data + bytes, data, bytes);
- memset(data, 0, bytes);
+ memmove(data + vbo + bytes, data + vbo, data_size - vbo);
+ memset(data + vbo, 0, bytes);
goto done;
}
--
2.43.0
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH ntfs] fs/ntfs3: fix slab-out-of-bounds write in attr_insert_range()
2026-07-09 22:05 [PATCH ntfs] fs/ntfs3: fix slab-out-of-bounds write in attr_insert_range() Xiang Mei (Microsoft)
@ 2026-09-28 17:22 ` Konstantin Komarov
0 siblings, 0 replies; 2+ messages in thread
From: Konstantin Komarov @ 2026-09-28 17:22 UTC (permalink / raw)
To: Xiang Mei (Microsoft)
Cc: ntfs3, linux-kernel, AutonomousCodeSecurity, tgopinath, kys
On 7/10/26 00:05, Xiang Mei (Microsoft) wrote:
> When fallocate(FALLOC_FL_INSERT_RANGE) grows a still-resident ntfs3
> attribute, attr_insert_range() shifts the inline data using the insert
> length 'bytes' as both the destination offset and the copy size:
>
> memmove(data + bytes, data, bytes);
>
> Both are wrong: the shift must start at the insertion point 'vbo' and
> move only the data past it (data_size - vbo). When bytes > data_size the
> memmove runs off the end of the data_size + bytes buffer and overflows
> the adjacent slab object.
>
> Since vbo < data_size is already enforced above, the reworked offsets stay
> within the data_size + bytes buffer and cannot under/overflow.
>
> BUG: KASAN: slab-out-of-bounds in attr_insert_range (fs/ntfs3/attrib.c:2581)
> Write of size 512 at addr ffff8880135e8b10 by task exploit/142
> ...
> __asan_memmove (mm/kasan/shadow.c:95)
> attr_insert_range (fs/ntfs3/attrib.c:2581)
> ntfs_fallocate (fs/ntfs3/file.c:618)
> vfs_fallocate (fs/open.c:338)
> __x64_sys_fallocate (fs/open.c:362)
> ...
>
> Fixes: 9256ec35359f ("fs/ntfs3: Refactoring attr_insert_range to restore after errors")
> Reported-by: AutonomousCodeSecurity@microsoft.com
> Signed-off-by: Xiang Mei (Microsoft) <xmei5@asu.edu>
> ---
> fs/ntfs3/attrib.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/fs/ntfs3/attrib.c b/fs/ntfs3/attrib.c
> index c621a4c582f9..a9a2c2104fd6 100644
> --- a/fs/ntfs3/attrib.c
> +++ b/fs/ntfs3/attrib.c
> @@ -2578,8 +2578,8 @@ int attr_insert_range(struct ntfs_inode *ni, u64 vbo, u64 bytes)
> char *data = Add2Ptr(attr_b,
> le16_to_cpu(attr_b->res.data_off));
>
> - memmove(data + bytes, data, bytes);
> - memset(data, 0, bytes);
> + memmove(data + vbo + bytes, data + vbo, data_size - vbo);
> + memset(data + vbo, 0, bytes);
> goto done;
> }
>
Hello,
The patch was applied, thank you.
Regards,
Konstantin
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-28 17:22 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-09 22:05 [PATCH ntfs] fs/ntfs3: fix slab-out-of-bounds write in attr_insert_range() Xiang Mei (Microsoft)
2026-09-28 17:22 ` Konstantin Komarov
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®