* [PATCH] jfs: fix im_l2nbperiext shift out of bounds
@ 2025-09-25 2:58 Pedro Demarchi Gomes
0 siblings, 0 replies; only message in thread
From: Pedro Demarchi Gomes @ 2025-09-25 2:58 UTC (permalink / raw)
To: shaggy, duttaditya18, ghanshyam1898
Cc: jfs-discussion, linux-kernel, Pedro Demarchi Gomes,
syzbot+13ba7f3e9a17f77250fe
When reading im_l2nbperiext from disk, check if its value is valid.
Since im_l2nbperiext is the log2 of a 32 bit number, its maximum value is 31.
Reported-by: syzbot+13ba7f3e9a17f77250fe@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=13ba7f3e9a17f77250fe
Signed-off-by: Pedro Demarchi Gomes <pedrodemargomes@gmail.com>
---
fs/jfs/jfs_imap.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/fs/jfs/jfs_imap.c b/fs/jfs/jfs_imap.c
index ecb8e05b8b84..6abeb78c9eb4 100644
--- a/fs/jfs/jfs_imap.c
+++ b/fs/jfs/jfs_imap.c
@@ -124,6 +124,10 @@ int diMount(struct inode *ipimap)
atomic_set(&imap->im_numfree, le32_to_cpu(dinom_le->in_numfree));
imap->im_nbperiext = le32_to_cpu(dinom_le->in_nbperiext);
imap->im_l2nbperiext = le32_to_cpu(dinom_le->in_l2nbperiext);
+ if (imap->im_l2nbperiext > 31) {
+ jfs_err("diMount: invalid im_l2nbperiext");
+ return -EIO;
+ }
for (index = 0; index < MAXAG; index++) {
imap->im_agctl[index].inofree =
le32_to_cpu(dinom_le->in_agctl[index].inofree);
--
2.39.5
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2025-09-25 3:06 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-09-25 2:58 [PATCH] jfs: fix im_l2nbperiext shift out of bounds Pedro Demarchi Gomes
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®