From: Hui Peng <benquike@gmail.com>
To: Anders Larsen <al@alarsen.net>,
Matthias Goergens <matthias.goergens@gmail.com>
Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org,
stable@vger.kernel.org, Hui Peng <benquike@gmail.com>
Subject: [PATCH v5 0/6] fs/qnx6: fix buffer head leaks, double free, and inode validation
Date: Wed, 30 Sep 2026 08:19:41 +0000 [thread overview]
Message-ID: <20260930081947.511613-1-benquike@gmail.com> (raw)
This series addresses buffer head memory leaks, uninitialized pointer reads,
out-of-bounds array access, and superblock validation issues in the qnx6
filesystem driver.
All patches have been ported to the latest tip of mainline (551c722f4080)
and verified in QEMU KVM with CONFIG_KASAN=y and UBSAN enabled.
Changes in v5:
- 1/6: Restored commit description to accurately specify UBSAN
shift-out-of-bounds reports at both shifts in qnx6_block_map() as
requested by Matthias Goergens.
- 3/6: Used qs->sb_buf instead of sbi->sb_buf at label out: in
qnx6_fill_super() to prevent reading uninitialized sbi when mounting
mmi_fs images, fixing a general protection fault reported by Matthias.
- 4/6: Updated commit description to state that clearing sb_buf after
brelse() is defensive cleanup.
- Collected Tested-by and Reviewed-by tags from Matthias Goergens.
Hui Peng (6):
qnx6: validate di_filelevels in qnx6_iget() before accessing level
pointers
qnx6: release bh on error path in qnx6_block_map()
qnx6: release bh on error path in qnx6_fill_super()
qnx6: clear sb_buf after brelse in qnx6_mmi_fill_super()
qnx6: abort mount on superblock magic mismatch when silent is set in
qnx6_mmi_fill_super()
qnx6: validate sb_blocksize before dividing in qnx6_mmi_fill_super()
fs/qnx6/inode.c | 18 +++++++++++++++---
fs/qnx6/super_mmi.c | 7 ++++++-
2 files changed, 21 insertions(+), 4 deletions(-)
--
2.47.3
next reply other threads:[~2026-09-30 8:19 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 8:19 Hui Peng [this message]
2026-09-30 8:19 ` [PATCH v5 1/6] qnx6: validate di_filelevels in qnx6_iget() before accessing level pointers Hui Peng
2026-09-30 8:19 ` [PATCH v5 2/6] qnx6: release bh on error path in qnx6_block_map() Hui Peng
2026-09-30 8:19 ` [PATCH v5 3/6] qnx6: release bh on error path in qnx6_fill_super() Hui Peng
2026-09-30 8:19 ` [PATCH v5 4/6] qnx6: clear sb_buf after brelse in qnx6_mmi_fill_super() Hui Peng
2026-09-30 8:19 ` [PATCH v5 5/6] qnx6: abort mount on superblock magic mismatch when silent is set " Hui Peng
2026-09-30 8:19 ` [PATCH v5 6/6] qnx6: validate sb_blocksize before dividing " Hui Peng
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930081947.511613-1-benquike@gmail.com \
--to=benquike@gmail.com \
--cc=al@alarsen.net \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=matthias.goergens@gmail.com \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®