From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f171.google.com (mail-qk1-f171.google.com [209.85.222.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C9B7632863D for ; Thu, 11 Jun 2026 21:30:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781213433; cv=none; b=qsXWvIh/e+FDtcbQ8qBt1wPlMmAGD16PdSa1IqqJGomeLw53YIMxXhPvoP6gUpyyV1bw6nhOPOK02V18fOziurY/DQHzqaj/NRD+EyrQAkqwcYESb0WULBK9zszIXYHlNugj4lvbZ8gqMS3rMmHFzllbOXr/Ec/CqPhedPAVlB4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781213433; c=relaxed/simple; bh=1ojnM+ca62Hur14sQ1BvBHTUsOVDrBtkpIrpG/aMOlw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=kqE/O49HLmlkKvbkxMkbldybRfGWbiT3MwolyXlwgtzVeaTQN9kKacQz0Bg0y7VAc01tSZk3quMZbx/EJYQBULOwf/HNXVMOCFeq8AQ1HGeb0rhX2ixMhx0GobmU9N83hb5aCditn7cGRqsDz0V6o0DbdyBXI7HnYfAb6JbH+vo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=openai.com; spf=pass smtp.mailfrom=openai.com; dkim=pass (1024-bit key) header.d=openai.com header.i=@openai.com header.b=DhBcxowd; arc=none smtp.client-ip=209.85.222.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=openai.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=openai.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=openai.com header.i=@openai.com header.b="DhBcxowd" Received: by mail-qk1-f171.google.com with SMTP id af79cd13be357-91587626a3eso39297785a.2 for ; Thu, 11 Jun 2026 14:30:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openai.com; s=google; t=1781213431; x=1781818231; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=OgrHRlb31PNlK7ylFz1YKYLL0ZIzxKfy2sHe06P0fhM=; b=DhBcxowdTWEniaxZakVmdeNtYqZju6VUe9PKccDhwbenFs2NjSQH/ph1liNyNzFWe6 xLyQv0c1t7SdYQ8QB4Va61gE1TcJzIg5JCc9CEosHZCPwfRevnfOYpotSl+f45i2l1QN 6SKRzebn+zV92HeloeWnp2Xv+uiei6iaCS0EM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781213431; x=1781818231; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=OgrHRlb31PNlK7ylFz1YKYLL0ZIzxKfy2sHe06P0fhM=; b=r1xRwmuRuvD7aO3aUdWlwMNtn/NnfLjAlqDnL2WQf842CLxQcPEYHrXPx5knq3mn6P bB7BD/kK3319Y/bY7//RkkyzsmIaKPA8eLOFTMg8Jte5uIceYKScfPT/Mwaeoj8FbbiS QftpqyZ4RQBnVlHESpF5sBbGDn8kRxLvg4sEmEXZJxr/lVuvLj5R48aghoGND04bx/Zq VTt4/WgXhZbeEWM4gQfYjuvlBZwgWfj7D1ze3XOwztvuh3j3L35sOmnVmBhx9+5x/PhS jawr2LPZ+aw5hkTnBORTrG3Vs7JLqLPPIT6vewVBUlQjwDoZsemxXjX4KjSO+3guXjEQ lQXQ== X-Gm-Message-State: AOJu0Ywy3/dVJrvtcKV3xtFAGkR+cvNPP4+Ue5CTJRlO6FDtk5u3yjJn 6Zout2pHmaCSu0F/V82ttAXBsqEokFiswrCbCoamlwUI4rEtPaIYWuTdhu2HYJTVn6U= X-Gm-Gg: Acq92OFmapPr/tD0wTfHzn9an92wqudGSWrn/ylLnTHUvMjqiSF7KVfpgKq2oqFMJIB xEJ/e1686vfhf3CIUFOZZBgrMQpQ+xoveFB8SBa2ErS+FOzAW1x/EomYc9H9h61JTx+Sm7dfVPW MOEbcL9YvJ9SOEkiBV6TgzFt2y4Cap8lLI2CeK0gVKIo3QdbzTgzj/fttuUI6Yz/1SXl1FQw14R ZKNriesK4xZ75blN+fZY3fTtruzl96EEV6DpY0Hin1Ur14OZaW2bxVRwVKf4zhnJ5K6BLwuukSP KyxemfDOmAf8YOX82q/86g+TnaelwA06r0QytlstDTeAnpNFHbQ8z0UG8W7Lr1VlkEo7rmbQ+DO z3MWd1S6wjaIp9/13hbNcPLlhjnAe/EibRPMD9grKMOizD0wihSEqFVg1pSdkUoGe9XaFBiAV0D tb8+Abn76pmvPE+/q0uKXb3vSQNs0hLYuAKbJ56voGMOvGht3EOksvBl3oGidcoRANvxZo4obFH nDHmT3npl1Fc78vYvIREfAGZik3lf2HRqU= X-Received: by 2002:a05:620a:2704:b0:914:7e9a:2716 with SMTP id af79cd13be357-9160ae0ac85mr738496085a.38.1781213430744; Thu, 11 Jun 2026 14:30:30 -0700 (PDT) Received: from com-75606.node.ndb.openai.org ([209.249.37.146]) by smtp.gmail.com with ESMTPSA id af79cd13be357-91619f06835sm29843685a.14.2026.06.11.14.30.29 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Thu, 11 Jun 2026 14:30:30 -0700 (PDT) From: Kyle Zeng To: jfs-discussion@lists.sourceforge.net Cc: linux-kernel@vger.kernel.org, Christian Brauner , Dave Kleikamp , outbounddisclosures@openai.com, Kyle Zeng , stable@vger.kernel.org Subject: [PATCH] jfs: reject malformed xattr entries in ea_get Date: Thu, 11 Jun 2026 14:30:26 -0700 Message-ID: <20260611213026.12684-1-kylebot@openai.com> X-Mailer: git-send-email 2.54.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit JFS checks that an extended attribute list's top-level size field matches the inode EA descriptor before returning the list to callers. That is not enough to prove that every entry in the list is contained within that size. __jfs_setxattr() walks existing entries and trusts EA_SIZE(ea). A crafted filesystem can store an inline EA list whose aggregate size is self-consistent, but whose first entry advertises a value length that extends past END_EALIST(). Replacing that attribute then subtracts the oversized old entry from xattr_size and appends the replacement at an out-of-bounds address. Validate each EA entry in ea_get() before any get, list, or set path can consume it. Reject entries whose header is truncated, whose encoded length crosses the end of the list, or whose encoded name lacks the required trailing NUL byte. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5.5 Signed-off-by: Kyle Zeng --- fs/jfs/xattr.c | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) diff --git a/fs/jfs/xattr.c b/fs/jfs/xattr.c index 11d7f74d207b..a7432cfabea2 100644 --- a/fs/jfs/xattr.c +++ b/fs/jfs/xattr.c @@ -118,6 +118,33 @@ static inline int copy_name(char *buffer, struct jfs_ea *ea) /* Forward references */ static void ea_release(struct inode *inode, struct ea_buffer *ea_buf); +static bool ea_entries_valid(struct jfs_ea_list *ealist, int size) +{ + char *p = (char *)FIRST_EA(ealist); + char *end = (char *)ealist + size; + + if (size < sizeof(*ealist)) + return false; + + while (p < end) { + struct jfs_ea *ea = (struct jfs_ea *)p; + int ea_size; + + if (p + sizeof(*ea) > end) + return false; + + ea_size = EA_SIZE(ea); + if (p + ea_size > end) + return false; + if (ea->name[ea->namelen] != '\0') + return false; + + p += ea_size; + } + + return p == end; +} + /* * NAME: ea_write_inline * @@ -574,6 +601,15 @@ static int ea_get(struct inode *inode, struct ea_buffer *ea_buf, int min_size) goto clean_up; } + if (!ea_entries_valid(ea_buf->xattr, ea_size)) { + pr_err("%s: invalid extended attribute entry\n", __func__); + print_hex_dump(KERN_ERR, "", DUMP_PREFIX_ADDRESS, 16, 1, + ea_buf->xattr, ea_size, 1); + ea_release(inode, ea_buf); + rc = -EIO; + goto clean_up; + } + return ea_size; clean_up: -- 2.54.0