From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f173.google.com (mail-pf1-f173.google.com [209.85.210.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0697638B124 for ; Fri, 17 Jul 2026 18:41:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.173 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784313667; cv=none; b=TrWDRYgE/mNGAoFrA6jiw6THNuGbjqYpySwbVpJQKQntTQxWtTFESqSs4CvxZxkYEqTV069qUl4tc7ynR+WGI8A8ueQ8TAEPRcJjnH/Mjnmnn4MFJfxiZDkzOAWV0Abe+5sygtaZLvomu4vEm5wr9Z4Vauczl5KAiG1HZPbuLKY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784313667; c=relaxed/simple; bh=Ce+GGqFiTLMHfW5dPi+gtgJchI9OMnMhC5xDJesnAQc=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=RpD6GcAfGmcaUsjLLo84UGpvPXm5XwnA0H/DeWTbrrKtdVJsFhE9emlV/rcljqeVr37rVrxVzieHhoxA6JBRSTI3hFqA+NyfipZXe8GPVVhhfCpqU58NT7feCb+QxeE0VZx49J6jNBMZubmaRzD9/chnzeig0nNG74qtSqZUIpk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=artiphishell.com; spf=pass smtp.mailfrom=artiphishell.com; dkim=pass (2048-bit key) header.d=artiphishell.com header.i=@artiphishell.com header.b=Dc6EMBl6; arc=none smtp.client-ip=209.85.210.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=artiphishell.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=artiphishell.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=artiphishell.com header.i=@artiphishell.com header.b="Dc6EMBl6" Received: by mail-pf1-f173.google.com with SMTP id d2e1a72fcca58-8485ef63b68so7794922b3a.1 for ; Fri, 17 Jul 2026 11:41:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=artiphishell.com; s=google; t=1784313662; x=1784918462; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=42Qce/R3+jUmCTk9r7G4X4HK+Fk+lNItZ4O4ND+zy3c=; b=Dc6EMBl6pD5Lm5pO5xtjpOPYUK6r9ZkmdDIAlE9zJlFby/bM1vgO5UDpumU2lpwk/8 4olMj1z2cNP+BlsFc3jTUPX7t/il0UZ+ihTQbYfnlpRcxWM2qA+WLlazzLs/uFtiq1Wv HVkzdCi3I8v2yPXL43I9FagaEFv7mKTCHENrsW7cddpvFWD3mxb74nE797QKp5bqRJF3 5iBWrS4s1QDfIUtEYVw21pq4kOti9K8zY06TbHixqwqS0TeBc8GYjKK3fZGgphYequMx rC6VjfgdlG90guVuu7w6QwNyDe5fY0Ank0wAf5USCEslArw8/nzk0Tq0kiu5k0BJDNK3 GEvA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784313662; x=1784918462; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=42Qce/R3+jUmCTk9r7G4X4HK+Fk+lNItZ4O4ND+zy3c=; b=gf2jf+biSC2M2oDtjs9edmDx4M+uRmuTAy1t7Dlz+ow71TUulV6j6xv8G3Mdf2UMSE 9bB1qKNeRi04rkL3JMGSgwZgUowWkhSktq/2sC6jRHxa/OXVP5VrrhXMFZirgQVQ84UL 1U1dibV7o+35AHJAWCJKwINye79lTssrLHeYKCZ1pGr5SX6wfRDcixrNFgQGgtmO9O+V GBw5pzborQ6dZlSxQcsNjA+DPQSrQkdlEQXcCzOUphLANt2ldvJlkuYQJjohGG36lXjw VbF9/gC2OxLeqTxtHMMltM6vygPYlGEU1ZLeORbObJHgztK/YokYPICDE0lnoBjppR0T UQQg== X-Gm-Message-State: AOJu0YwrpuaZqrZSEzydRBY6j2fWkuavKYEgAAig+cSQwTSV5mZVEorN U2+sSmqjDYSX8tNDm+fb4jYKpeCdRZ9On2H3HA6V8rHocSR5fHgz0JXvtWPXSM3qSDk2 X-Gm-Gg: AfdE7cmpQVltH6q6yg+2mPsaS23woxrgEAfqNm8uKXmiQd0ktBHpd3cHssZEZRAw7mc ocqTtiXs6V7LWn8PoAwkFceR7WZYXbyjf2sJtzYb7rPNIjA87wJq+gRW8LIMpYdvlGNmHdqqLwO Q8/euhUMNOT5wAaz7kC2flzSbZLzHAF5cPW/8Mg54vFO96YBfLSw88SbII51onUw8g/iVMQfiG4 GdFUNm6Gl+Fb2+xJc7wLf+O2LELRTiqj5rVGSQc0W5eDbysZvhVgXnrlfMUnwsZoTAD/zxSZZ/h 2M2X3M7Zz1u7fMXvwr2x6WgEWhHWAGVnT9ShAu7FmvoDcQjm2Ar9amSmA1CbhBJ9M2lbK14AC6Q rsoT9P2KrQBwBVfxAoIk4uSpk7tOqkQqP/a6U3y9EqN2bixpS/Xzu+M48c+dKbAQIo16fwd8gP+ chHR4= X-Received: by 2002:a05:6a21:4c0c:b0:3bf:a698:ce4c with SMTP id adf61e73a8af0-3c3ad945355mr4169904637.58.1784313662281; Fri, 17 Jul 2026 11:41:02 -0700 (PDT) Received: from nixos ([2001:579:62a8:47:e2cb:6b8:ea21:46f2]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2900a37sm7607434c88.0.2026.07.17.11.41.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 11:41:01 -0700 (PDT) From: Jay Vadayath To: Jan Kara Cc: linux-kernel@vger.kernel.org, Jay Vadayath Subject: [PATCH] udf: bound lengthAllocDescs from unallocated space entry Date: Fri, 17 Jul 2026 11:40:19 -0700 Message-ID: <20260717184021.13476-1-jay@artiphishell.com> X-Mailer: git-send-email 2.51.2 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit udf_read_inode() copies the on-disk lengthAllocDescs field of a USE (unallocSpaceEntry) inode into iinfo->i_lenAlloc without checking that it fits in the i_data buffer that is subsequently allocated for the inode. udf_count_free_table(), called from udf_statfs(), then walks the allocation descriptor array up to i_lenAlloc bytes, so a crafted UDF image with lengthAllocDescs larger than (blocksize - sizeof(struct unallocSpaceEntry)) causes udf_get_fileshortad() to read past the end of the kmalloc'd i_data buffer. KASAN report from mounting a crafted UDF image and calling statfs() from an unprivileged process: BUG: KASAN: slab-out-of-bounds in udf_get_fileshortad+0x126/0x130 Read of size 4 at addr ffff8880042137d8 by task poc/65 Call Trace: dump_stack_lvl+0x53/0x70 print_report+0xce/0x610 kasan_report+0xce/0x100 udf_get_fileshortad+0x126/0x130 udf_current_aext+0x3c4/0xa10 udf_next_aext+0x241/0x440 udf_statfs+0xb7d/0x11c0 statfs_by_dentry+0x117/0x1e0 user_statfs+0xac/0x130 __do_sys_statfs+0x80/0xe0 do_syscall_64+0x102/0x5a0 entry_SYSCALL_64_after_hwframe+0x77/0x7f Reject USE inodes whose lengthAllocDescs would place descriptors past the end of the i_data buffer, mirroring the checks the rest of the UDF code performs on descriptor lengths. This bug was discovered by Artiphishell's vTriage pipeline, which generated a userspace reproducer that reliably triggers the KASAN report on an unpatched kernel. The fix below was drafted with the Claude coding assistant; a userspace reproducer (and the crafted UDF image) is available on request. Assisted-by: Claude:claude-opus-4-7 Signed-off-by: Jay Vadayath --- fs/udf/inode.c | 7 +++++++ 1 file changed, 7 insertions(+) --- a/fs/udf/inode.c +++ b/fs/udf/inode.c @@ -1475,6 +1475,13 @@ iinfo->i_lenAlloc = le32_to_cpu( ((struct unallocSpaceEntry *)bh->b_data)-> lengthAllocDescs); + /* + * Sanity check the length of allocation descriptors so we do + * not read past the end of the allocated i_data buffer when + * walking them later (e.g. from udf_count_free_table()). + */ + if (iinfo->i_lenAlloc > bs - sizeof(struct unallocSpaceEntry)) + goto out; ret = udf_alloc_i_data(inode, bs - sizeof(struct unallocSpaceEntry)); if (ret)