* Re: [PATCH] ecryptfs: validate auth tok payload and sKEK size
[not found] <20261001203952.1294581-1-adrianox@gmail.com>
@ 2026-10-01 20:39 ` syzbot
0 siblings, 0 replies; only message in thread
From: syzbot @ 2026-10-01 20:39 UTC (permalink / raw)
To: adrianox; +Cc: adrianox, syzkaller-bugs, linux-kernel
> #syz test
"" does not look like a valid git branch or commit.
> fs/ecryptfs/ecryptfs_kernel.h | 6 ++++++
> fs/ecryptfs/keystore.c | 7 +++++++
> 2 files changed, 13 insertions(+)
>
> diff --git a/fs/ecryptfs/ecryptfs_kernel.h b/fs/ecryptfs/ecryptfs_kernel.h
> index 58165928ed1e..4315c18ba1cd 100644
> --- a/fs/ecryptfs/ecryptfs_kernel.h
> +++ b/fs/ecryptfs/ecryptfs_kernel.h
> @@ -88,6 +88,9 @@ ecryptfs_get_encrypted_key_payload_data(struct key *key)
> if (!payload)
> return ERR_PTR(-EKEYREVOKED);
>
> + if (payload->payload_datalen < sizeof(struct ecryptfs_auth_tok))
> + return ERR_PTR(-EINVAL);
> +
> return (struct ecryptfs_auth_tok *)payload->payload_data;
> }
>
> @@ -124,6 +127,9 @@ ecryptfs_get_key_payload_data(struct key *key)
> if (!ukp)
> return ERR_PTR(-EKEYREVOKED);
>
> + if (ukp->datalen < sizeof(struct ecryptfs_auth_tok))
> + return ERR_PTR(-EINVAL);
> +
> return (struct ecryptfs_auth_tok *)ukp->data;
> }
>
> diff --git a/fs/ecryptfs/keystore.c b/fs/ecryptfs/keystore.c
> index 51651314b7a6..7f2dbc81fcbc 100644
> --- a/fs/ecryptfs/keystore.c
> +++ b/fs/ecryptfs/keystore.c
> @@ -477,6 +477,13 @@ ecryptfs_verify_auth_tok_from_key(struct key *auth_tok_key,
> rc = -EINVAL;
> goto out;
> }
> + if ((*auth_tok)->token_type == ECRYPTFS_PASSWORD
> + && (*auth_tok)->token.password.session_key_encryption_key_bytes
> + > ECRYPTFS_MAX_KEY_BYTES) {
> + printk(KERN_ERR "Invalid password auth_tok sKEK size\n");
> + rc = -EINVAL;
> + goto out;
> + }
> out:
> return rc;
> }
> --
> 2.51.0
>
^ permalink raw reply [flat|nested] only message in thread