From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Nihar Chaithanya <niharchaithanya@gmail.com>,
syzbot+412dea214d8baa3f7483@syzkaller.appspotmail.com,
Dave Kleikamp <dave.kleikamp@oracle.com>,
Sasha Levin <sashal@kernel.org>,
shaggy@kernel.org, peili.dev@gmail.com, rbrasga@uci.edu,
aha310510@gmail.com, ghanshyam1898@gmail.com, eadavis@qq.com,
jfs-discussion@lists.sourceforge.net
Subject: [PATCH AUTOSEL 5.15 26/36] jfs: add a check to prevent array-index-out-of-bounds in dbAdjTree
Date: Sun, 24 Nov 2024 08:51:40 -0500 [thread overview]
Message-ID: <20241124135219.3349183-26-sashal@kernel.org> (raw)
In-Reply-To: <20241124135219.3349183-1-sashal@kernel.org>
From: Nihar Chaithanya <niharchaithanya@gmail.com>
[ Upstream commit a174706ba4dad895c40b1d2277bade16dfacdcd9 ]
When the value of lp is 0 at the beginning of the for loop, it will
become negative in the next assignment and we should bail out.
Reported-by: syzbot+412dea214d8baa3f7483@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=412dea214d8baa3f7483
Tested-by: syzbot+412dea214d8baa3f7483@syzkaller.appspotmail.com
Signed-off-by: Nihar Chaithanya <niharchaithanya@gmail.com>
Signed-off-by: Dave Kleikamp <dave.kleikamp@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/jfs/jfs_dmap.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/fs/jfs/jfs_dmap.c b/fs/jfs/jfs_dmap.c
index 7486c79a5058b..e6cbe4c982c58 100644
--- a/fs/jfs/jfs_dmap.c
+++ b/fs/jfs/jfs_dmap.c
@@ -2957,6 +2957,9 @@ static void dbAdjTree(dmtree_t *tp, int leafno, int newval, bool is_ctl)
/* bubble the new value up the tree as required.
*/
for (k = 0; k < le32_to_cpu(tp->dmt_height); k++) {
+ if (lp == 0)
+ break;
+
/* get the index of the first leaf of the 4 leaf
* group containing the specified leaf (leafno).
*/
--
2.43.0
next prev parent reply other threads:[~2024-11-24 13:53 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-11-24 13:51 [PATCH AUTOSEL 5.15 01/36] drm/vc4: hvs: Set AXI panic modes for the HVS Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 02/36] drm: panel-orientation-quirks: Add quirk for AYA NEO 2 model Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 03/36] drm/mcde: Enable module autoloading Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 04/36] drm/radeon/r600_cs: Fix possible int overflow in r600_packet3_check() Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 05/36] r8169: don't apply UDP padding quirk on RTL8126A Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 06/36] samples/bpf: Fix a resource leak Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 07/36] net: fec_mpc52xx_phy: Use %pa to format resource_size_t Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 08/36] net: ethernet: fs_enet: " Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 09/36] net/sched: cbs: Fix integer overflow in cbs_set_port_rate() Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 10/36] af_packet: avoid erroring out after sock_init_data() in packet_create() Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 11/36] Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create() Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 12/36] net: af_can: do not leave a dangling sk pointer in can_create() Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 13/36] net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 14/36] net: inet: do not leave a dangling sk pointer in inet_create() Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 15/36] net: inet6: do not leave a dangling sk pointer in inet6_create() Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 16/36] wifi: ath5k: add PCI ID for SX76X Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 17/36] wifi: ath5k: add PCI ID for Arcadyan devices Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 18/36] drm/panel: simple: Add Microchip AC69T88A LVDS Display panel Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 19/36] drm/amdgpu: clear RB_OVERFLOW bit when enabling interrupts for vega20_ih Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 20/36] drm/amdgpu: Dereference the ATCS ACPI buffer Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 21/36] drm/amdgpu: refine error handling in amdgpu_ttm_tt_pin_userptr Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 22/36] dma-debug: fix a possible deadlock on radix_lock Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 23/36] jfs: array-index-out-of-bounds fix in dtReadFirst Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 24/36] jfs: fix shift-out-of-bounds in dbSplit Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 25/36] jfs: fix array-index-out-of-bounds in jfs_readdir Sasha Levin
2024-11-24 13:51 ` Sasha Levin [this message]
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 27/36] net: enetc: add i.MX95 EMDIO support Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 28/36] drm/amdgpu: skip amdgpu_device_cache_pci_state under sriov Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 29/36] drm/amdgpu: set the right AMDGPU sg segment limitation Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 30/36] wifi: ipw2x00: libipw_rx_any(): fix bad alignment Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 31/36] wifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw() Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 32/36] Bluetooth: hci_core: Fix not checking skb length on hci_acldata_packet Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 33/36] ASoC: hdmi-codec: reorder channel allocation list Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 34/36] rocker: fix link status detection in rocker_carrier_init() Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 35/36] net/neighbor: clear error in case strict check is not set Sasha Levin
2024-11-24 13:51 ` [PATCH AUTOSEL 5.15 36/36] netpoll: Use rcu_access_pointer() in __netpoll_setup Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20241124135219.3349183-26-sashal@kernel.org \
--to=sashal@kernel.org \
--cc=aha310510@gmail.com \
--cc=dave.kleikamp@oracle.com \
--cc=eadavis@qq.com \
--cc=ghanshyam1898@gmail.com \
--cc=jfs-discussion@lists.sourceforge.net \
--cc=linux-kernel@vger.kernel.org \
--cc=niharchaithanya@gmail.com \
--cc=peili.dev@gmail.com \
--cc=rbrasga@uci.edu \
--cc=shaggy@kernel.org \
--cc=stable@vger.kernel.org \
--cc=syzbot+412dea214d8baa3f7483@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®