From: Matthias Goergens <matthias.goergens@gmail.com>
To: Jan Kara <jack@suse.cz>
Cc: Christian Brauner <brauner@kernel.org>,
Yichong Chen <chenyichong@uniontech.com>,
linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [PATCH 1/2] isofs: validate directory records in isofs_read_level3_size()
Date: Tue, 22 Sep 2026 22:01:36 +0800 [thread overview]
Message-ID: <20260922140137.1768064-2-matthias.goergens@gmail.com> (raw)
In-Reply-To: <20260922140137.1768064-1-matthias.goergens@gmail.com>
isofs_read_level3_size() walks the multi-extent directory records of a
file and dereferences de->size and de->flags for each one without ever
checking the record's length byte. A record with a short length placed
near the end of a block makes those fixed-field reads run past the
record, and for a record at the end of the last block of a page, past
the buffer.
readdir, lookup and the NFS get_parent path have validated every record
with isofs_dir_record_valid() since commit e2ee4078ec58 ("isofs:
validate directory records consistently"). Use the same helper here.
It rejects records shorter than the fixed part, records whose name
would not fit, and records that would run past the block, so the
straddling-record copy below can no longer be reached with a bad
length.
Found by fuzzing fs/isofs in a userspace harness with ASan
(heap-buffer-overflow reads in isonum_733(de->size)).
Signed-off-by: Matthias Goergens <matthias.goergens@gmail.com>
---
fs/isofs/inode.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/fs/isofs/inode.c b/fs/isofs/inode.c
index 337836a0a170..c9bc1f479161 100644
--- a/fs/isofs/inode.c
+++ b/fs/isofs/inode.c
@@ -1208,6 +1208,14 @@ static int isofs_read_level3_size(struct inode *inode)
continue;
}
+ if (!isofs_dir_record_valid(de, offset, bufsize)) {
+ printk(KERN_NOTICE "iso9660: Corrupted directory entry in block %lu of inode %llu\n",
+ block, inode->i_ino);
+ brelse(bh);
+ kfree(tmpde);
+ return -EIO;
+ }
+
block_saved = block;
offset_saved = offset;
offset += de_len;
--
2.55.0
next prev parent reply other threads:[~2026-09-22 14:01 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 14:01 [PATCH 0/2] isofs: simplify the level 3 directory record walk Matthias Goergens
2026-09-22 14:01 ` Matthias Goergens [this message]
2026-09-23 13:37 ` [PATCH 1/2] isofs: validate directory records in isofs_read_level3_size() Jan Kara
2026-09-23 15:32 ` Matthias Goergens
2026-09-23 17:01 ` Jan Kara
2026-09-22 14:01 ` [PATCH 2/2] isofs: drop support for level 3 records straddling blocks Matthias Goergens
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260922140137.1768064-2-matthias.goergens@gmail.com \
--to=matthias.goergens@gmail.com \
--cc=brauner@kernel.org \
--cc=chenyichong@uniontech.com \
--cc=jack@suse.cz \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®