* [PATCH V2] fs: jfs: fix shift-out-of-bounds in dbDiscardAG
@ 2022-10-25 15:20 Hoi Pok Wu
2022-10-27 22:36 ` Dave Kleikamp
0 siblings, 1 reply; 2+ messages in thread
From: Hoi Pok Wu @ 2022-10-25 15:20 UTC (permalink / raw)
To: shaggy
Cc: Hoi Pok Wu, jfs-discussion, linux-kernel,
syzbot+f0e0fcf3cd1047ae60ad, syzkaller-bugs
This should be applied to most URSAN bugs found recently by syzbot,
by guarding the dbMount. As syzbot feeding rubbish into the bmap
descriptor.
Signed-off-by: Hoi Pok Wu <wuhoipok@gmail.com>
---
V1->2: guarding the corrupted data structure from dbMount instead
fs/jfs/jfs_dmap.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/fs/jfs/jfs_dmap.c b/fs/jfs/jfs_dmap.c
index e1cbfbb60303..765838578a72 100644
--- a/fs/jfs/jfs_dmap.c
+++ b/fs/jfs/jfs_dmap.c
@@ -198,6 +198,11 @@ int dbMount(struct inode *ipbmap)
goto err_release_metapage;
}
+ if (((bmp->db_mapsize - 1) >> bmp->db_agl2size) > MAXAG) {
+ err = -EINVAL;
+ goto err_release_metapage;
+ }
+
for (i = 0; i < MAXAG; i++)
bmp->db_agfree[i] = le64_to_cpu(dbmp_le->dn_agfree[i]);
bmp->db_agsize = le64_to_cpu(dbmp_le->dn_agsize);
--
2.38.1
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH V2] fs: jfs: fix shift-out-of-bounds in dbDiscardAG
2022-10-25 15:20 [PATCH V2] fs: jfs: fix shift-out-of-bounds in dbDiscardAG Hoi Pok Wu
@ 2022-10-27 22:36 ` Dave Kleikamp
0 siblings, 0 replies; 2+ messages in thread
From: Dave Kleikamp @ 2022-10-27 22:36 UTC (permalink / raw)
To: Hoi Pok Wu
Cc: jfs-discussion, linux-kernel, syzbot+f0e0fcf3cd1047ae60ad,
syzkaller-bugs
Applied.
Thanks,
Shaggy
On 10/25/22 10:20AM, Hoi Pok Wu wrote:
> This should be applied to most URSAN bugs found recently by syzbot,
> by guarding the dbMount. As syzbot feeding rubbish into the bmap
> descriptor.
>
> Signed-off-by: Hoi Pok Wu <wuhoipok@gmail.com>
> ---
> V1->2: guarding the corrupted data structure from dbMount instead
> fs/jfs/jfs_dmap.c | 5 +++++
> 1 file changed, 5 insertions(+)
>
> diff --git a/fs/jfs/jfs_dmap.c b/fs/jfs/jfs_dmap.c
> index e1cbfbb60303..765838578a72 100644
> --- a/fs/jfs/jfs_dmap.c
> +++ b/fs/jfs/jfs_dmap.c
> @@ -198,6 +198,11 @@ int dbMount(struct inode *ipbmap)
> goto err_release_metapage;
> }
>
> + if (((bmp->db_mapsize - 1) >> bmp->db_agl2size) > MAXAG) {
> + err = -EINVAL;
> + goto err_release_metapage;
> + }
> +
> for (i = 0; i < MAXAG; i++)
> bmp->db_agfree[i] = le64_to_cpu(dbmp_le->dn_agfree[i]);
> bmp->db_agsize = le64_to_cpu(dbmp_le->dn_agsize);
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2022-10-27 22:36 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2022-10-25 15:20 [PATCH V2] fs: jfs: fix shift-out-of-bounds in dbDiscardAG Hoi Pok Wu
2022-10-27 22:36 ` Dave Kleikamp
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®