From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f169.google.com (mail-qk1-f169.google.com [209.85.222.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2DCC33314C4 for ; Thu, 11 Jun 2026 21:36:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.169 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781213801; cv=none; b=GGH988xrQmJH5RWEc8SHPKu1osL3G+Ly0foigLNZMscOTKJ9UvuoIOXv68gT9qwaAaC9P/mGazrhQYSAfrvNxZl9pBlPmbKcU+BhSvCmac9RvkpmQ00VJiNH1a1o6623UsvyCGGWdYnYqM6LB7SMNatNQUj2sPCVLmMh2ULGDGQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781213801; c=relaxed/simple; bh=rCy4MKRD4DItWRmCVcwOXd06fhDsk/KffrTeKEM0W2E=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=HTfW36zIiy+HdVbBCdhVh/pJ7BB0AlvR6OQq/cX78iBF55XOlxnpzih5Y1ooiRs0nVfLY5Ruqpi80cQoqWYmZ1UhjAdL4OvW96EmWjW3YvE/OpyNDeZyFUzVnCK+31TP3pqMZDiGHUkp/q/ZAG7QzokfPvJ0goK/6LiTjXGkFno= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=openai.com; spf=pass smtp.mailfrom=openai.com; dkim=pass (1024-bit key) header.d=openai.com header.i=@openai.com header.b=POOJOxl7; arc=none smtp.client-ip=209.85.222.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=openai.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=openai.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=openai.com header.i=@openai.com header.b="POOJOxl7" Received: by mail-qk1-f169.google.com with SMTP id af79cd13be357-9156ceb55ffso30375585a.0 for ; Thu, 11 Jun 2026 14:36:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openai.com; s=google; t=1781213799; x=1781818599; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=5pTXqZmvh94vSCva//3FoXkgQvXuaoXCLS2XExWeicI=; b=POOJOxl7KK9BwnoewRyIImUfGUmSt/IE/wxxzfS/76D768qs5TDZF9a5Tv/qmD7N/1 tMtK1fD3w+7ghK2xZn8vBVOGr2OsHgIDdN5ZLPgwKCSoYhfJn8jhTNJEu1xRSgK1uOnQ 1zlFAT6VfeI+bQ32ogy8MojlERXHt6sLtuLnE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781213799; x=1781818599; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=5pTXqZmvh94vSCva//3FoXkgQvXuaoXCLS2XExWeicI=; b=jdEmAmvFgXJZyYLFowvBEHWiyBisW5N2Q1eRaymiQsgOjNukoANHs4u9fHo/im38QX /z7LRRkQ4KLRGVseLhR8xOeWKCXxrdSk9jW5dqnL18lKeFqQuFeZ0QDKEkYzxawKMA0F y1kH/hFVfJWTa7XVZ29pVjjPeEjZwQmH4RiJoSq9L4GyPTG78NdNoQeu5qT1/+Y1uI3q DgiCnRsk/g3qMXUjzR5ZKdw6wN8Vw97moo6LZEFltldpSca1IIxKDTRSV3RGrdRaels7 2qoSG16likbrNATZQL9lDVm/EMORk0KQA7SKZ1gQMhNWsUYdtfdISyM1EvBacUzKpF20 N7/w== X-Gm-Message-State: AOJu0YwBczhOlqi2UZO7oPaXNSmzBvrg+VDoFSweMj0bs7OBuEtAuQ3J 9wVFFCJTt/US385Ro4eq1KYiokO+40nRLoCw686Dp6oaVQwuPtbOToOu2zsuErlNFlxaSJqssDI aNt5482c= X-Gm-Gg: Acq92OFkLGPoi+o6PKOA+DWCxDs2cQf5D6Utwl5Q82DpGv4CJUg19Toxxx8aaq2TLYY Z1q6stdG7qPKtA9xPUJCmwC06WYPzBT6EZZrgkXYm6dDwCZZXTpTpJ7NtQyqpkaA4VsGH8FReXk kTvyxC97W0sIsSy5UfUN9SMmOdEYZh2Aa8ZWXWJIRgQ+rBlHgId8x2Y6VcDEF2aMpgc7tspIBo2 At7cr2jvfW0dErzlohdevy+Y3ftRi/6FDv31Jf6da2rANeg5pW5ZC8LMZQCBhRV7xoBAWqKVNgZ bVBqoESGppQ3FHJ1UtYAsEvfZLkh7zwAiFxJ/LfDNs6oSO1/DoIQnf40mOMXbAlpkb2FIYukwaR fmNrST99TbzXzV+aAwfYbvMuPtaiuNVUDUyKT4K4P4ei8XXWOcIlEKtvr4emw0jwVlaLQtF1v9a mQL2e89S+/d/7hT8ejfHDqS72pPFFcbl/9O1XxsOQQnrBeYKIROFwHV/RYIbi5vGB2uKYVU98qp 4Ts9mQfa7a124EI3flH/+X7B9Jpp24e+kg= X-Received: by 2002:a05:620a:2b8b:b0:915:d5cd:8ce3 with SMTP id af79cd13be357-9160ac93e1dmr731902985a.14.1781213799197; Thu, 11 Jun 2026 14:36:39 -0700 (PDT) Received: from com-75606.node.ndb.openai.org ([209.249.37.146]) by smtp.gmail.com with ESMTPSA id af79cd13be357-9161a0080a7sm28437485a.26.2026.06.11.14.36.38 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Thu, 11 Jun 2026 14:36:38 -0700 (PDT) From: Kyle Zeng To: linux-kernel@vger.kernel.org Cc: Jan Kara , outbounddisclosures@openai.com, Kyle Zeng Subject: [PATCH] udf: validate partition reference before freeing blocks Date: Thu, 11 Jun 2026 14:36:35 -0700 Message-ID: <20260611213635.17198-1-kylebot@openai.com> X-Mailer: git-send-email 2.54.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit UDF long allocation descriptors can carry an on-disk partitionReferenceNum. The truncate/free path passes that value to udf_free_blocks(), which indexes s_partmaps[partition] before checking that partition is smaller than s_partitions. A crafted writable image with one partition and a long allocation descriptor that references partition 1 can therefore make udf_free_blocks() read past the allocated partition map array when truncating the file. Validate the partition reference before forming the map pointer. Also compare the checked end block, including the caller-supplied offset, against the partition length; the previous test computed blk but then compared logicalBlockNum + count. Assisted-by: Codex:gpt-5.5 Signed-off-by: Kyle Zeng --- fs/udf/balloc.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/fs/udf/balloc.c b/fs/udf/balloc.c index 807c493..9d5fe22 100644 --- a/fs/udf/balloc.c +++ b/fs/udf/balloc.c @@ -656,13 +656,21 @@ void udf_free_blocks(struct super_block *sb, struct inode *inode, struct kernel_lb_addr *bloc, uint32_t offset, uint32_t count) { + struct udf_sb_info *sbi = UDF_SB(sb); uint16_t partition = bloc->partitionReferenceNum; - struct udf_part_map *map = &UDF_SB(sb)->s_partmaps[partition]; + struct udf_part_map *map; uint32_t blk; + if (partition >= sbi->s_partitions) { + udf_debug("Invalid partition reference %u (partitions %u)\n", + partition, sbi->s_partitions); + return; + } + + map = &sbi->s_partmaps[partition]; if (check_add_overflow(bloc->logicalBlockNum, offset, &blk) || check_add_overflow(blk, count, &blk) || - bloc->logicalBlockNum + count > map->s_partition_len) { + blk > map->s_partition_len) { udf_debug("Invalid request to free blocks: (%d, %u), off %u, " "len %u, partition len %u\n", partition, bloc->logicalBlockNum, offset, count, -- 2.54.0