From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f178.google.com (mail-pl1-f178.google.com [209.85.214.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 23DE53314D9 for ; Sat, 23 May 2026 04:15:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.178 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779509714; cv=none; b=IygME8fV1D7OUqm4FfpDOPl655OblJiX1L1Uhy+Q64/sssmJgSObLsWnVk4Wiqn2AJgdjqJoVaYEc0rZzZuIvzj6oEJ80bR9c8i44utDnJt7kSUDHYkkoEUGSCSLJsbS1R8zldziXreOM7ShAmb+TYl6F5CbLOm4tGwZ7BxpqL0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779509714; c=relaxed/simple; bh=HqQecYhKN0ZfkC1p2kK45n+IQIFHeJl+F6L3+ooWb3c=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=YFjK+d8EWkra8qMkcMBMHaCeBjryIfBn8Z+iLPteV4VKOPg6Bwmo4ysieXSFkpY8c6USlxQITulDutNwziDy3jS1rWucM6f84vfIrwvKjjbjofO7+Ylngaib4lE70PwqDuA52HaJzR44X12mHod9fG1OOG9odSPJ7cOUY1W+4ok= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=HX0ZF9E5; arc=none smtp.client-ip=209.85.214.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="HX0ZF9E5" Received: by mail-pl1-f178.google.com with SMTP id d9443c01a7336-2ba21d32776so58738725ad.2 for ; Fri, 22 May 2026 21:15:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779509712; x=1780114512; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=WhzaN7BWimOMiqEoiQNjGpOIY4nGflNoP3vjImK4R3g=; b=HX0ZF9E53nSCx4qMVhBocRYY5tL9aJkW2QzveuNxJgl7B0i5Odrwwc1lGrAXDlwv9C ZyiF3XJaslnjSsyb+SUPj2rJ4n9CNqkB8zs2AP7EGqPHRPGJ25+DpPuftn2kmW7ndRmv I7ATIqFDSutUdHJ2ntswnqtDVYkgFILyCwU/akprtQ1khnT3siidbW78obBrDPSQb5mF J6jBm/UoHz9dQFzKyUMvq+4v14xBnXatm5nV8H0bMYQFqs11gkYzKTPVAElnlp29Xji2 yAC8vORLXBA5xBSPg9C/9HJm2NpIuxHz+DWvdP1O8RP5SuzxiBILJO/2QmR6LQecKWG6 1ZqQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779509712; x=1780114512; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=WhzaN7BWimOMiqEoiQNjGpOIY4nGflNoP3vjImK4R3g=; b=mdn/S7WttJZHAExKMMQSO5CQze3NPbozsZOoYgo0hazQtWp7VtoumqNUO7LUKcyNyu 7xXq4dfLY1uvQqS9l+QBgExi2//UK8hTtRqgn9s0B7Ziy32nuM4S2SlfcilHEObQCMnr xoigah5ExfO3O84pwiNzUnflSLTL1yB+Wmvt02SS4ZifvcSuncCBSWcaATe6f1FkxIow 2deZdK8zlf/GPhU/fl9EdUn5DSAHEeI/z4b+3jgI2hbJqgdVjy4AekqQ4EF4n5EnNG50 2np3jTjnA+Nxs6VFd1cDCiDtIWfb8MIPHC8ubstFCDkzTvtyJP8Fe3v2eC4/ZOgUEa4I t8nQ== X-Forwarded-Encrypted: i=1; AFNElJ9InX+BJ++VJkA9R1pGoE4hrDImPdpn7oS7icqE8zaUTPIjedpZI7KDnjusQtcGie4EZhco9tHdmlYT+/E=@vger.kernel.org X-Gm-Message-State: AOJu0Yw7dTIyWAxni7SETihe56Efuaoul+6Eruum6jzH9sjk+pUJ6QOd u5Hy94My+kgy7y/2erzTbJp1Y2xGJUZKJz9iQ4mr8jE2dpEPv7WS3sq1 X-Gm-Gg: Acq92OHC+Yjr4mapg1fMDDHQ6uSxe1oiPGlaD0vKVQuBftqFuM76LO93+Gs4m98ge5h zSmknQ9IjGF948d6b758QCzDs40CB6CJxSKmcqgF2b6igHbNKxz/+xs7pabnGHncPJTZwpjylvu rET9jp3cOzS8/6uGWXbMPpyiwuwDM5kCekC4Yo0eGMTlKSA+EGwEBD0rg8OVoYcWXULTI07Dral rgSuj4QI7vjlYiE4VfGpxtBsS5QDHeRRaKkY7ZohMQjflCoz3QH5ohw/AJ+BMmsa5+i7It0wPmd wobUqGcbqOm3cfgqphQJNA7P5T71s8Q6DseKYbmOmSNRyg+80Xv0EWZ8BWF9ahJ2hsZVBBNwycP E7zqR1lG9n9IwlAtTFKWqnVfOSAcq1i3s0wM1f9I00mYq/fRQVPaBdDuZbVsf7ud9z1TN3J8a6X o+0GfaB9q4Km3hqwzUqjREs8XGF83QlQ== X-Received: by 2002:a17:902:e88e:b0:2ba:839e:15cb with SMTP id d9443c01a7336-2beb05e306fmr70544575ad.27.1779509712129; Fri, 22 May 2026 21:15:12 -0700 (PDT) Received: from hyunchul-PC02.lge.net ([27.122.242.71]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2beb591a277sm31887675ad.80.2026.05.22.21.15.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 22 May 2026 21:15:11 -0700 (PDT) From: Hyunchul Lee To: Namjae Jeon Cc: Hyunchul Lee , linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v2 4/4] ntfs: add bounds check before accessing EA entries Date: Sat, 23 May 2026 13:14:23 +0900 Message-ID: <20260523041423.2726275-5-hyc.lee@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260523041423.2726275-1-hyc.lee@gmail.com> References: <20260523041423.2726275-1-hyc.lee@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit in ntfs_ea_lookup and ntfs_listxattr, this verifies that there is enough space in the EA entry before accessing the next_entry_offset field of the EA entry. Signed-off-by: Hyunchul Lee --- fs/ntfs/ea.c | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/fs/ntfs/ea.c b/fs/ntfs/ea.c index c4a4a3e3e599..0cd192752b7c 100644 --- a/fs/ntfs/ea.c +++ b/fs/ntfs/ea.c @@ -53,11 +53,11 @@ static int ntfs_ea_lookup(char *ea_buf, s64 ea_buf_size, const char *name, loff_t offset, p_ea_size; unsigned int next; - if (ea_buf_size < sizeof(struct ea_attr)) - goto out; - offset = 0; do { + if (ea_buf_size - offset < sizeof(struct ea_attr)) + break; + p_ea = (const struct ea_attr *)&ea_buf[offset]; next = le32_to_cpu(p_ea->next_entry_offset); p_ea_size = next ? next : (ea_buf_size - offset); @@ -479,13 +479,13 @@ ssize_t ntfs_listxattr(struct dentry *dentry, char *buffer, size_t size) if (ea_info_qsize > ea_buf_size || ea_info_qsize == 0) goto out; - if (ea_info_qsize < sizeof(struct ea_attr)) { - err = -EIO; - goto out; - } - offset = 0; do { + if (ea_info_qsize - offset < sizeof(struct ea_attr)) { + err = -EIO; + goto out; + } + p_ea = (const struct ea_attr *)&ea_buf[offset]; next = le32_to_cpu(p_ea->next_entry_offset); ea_size = next ? next : (ea_info_qsize - offset); -- 2.43.0