* [syzbot] KASAN: slab-out-of-bounds Write in utf32_to_utf8
@ 2026-10-05 15:12 syzbot
2026-10-06 5:53 ` Forwarded: [PATCH] jfs: fix slab-out-of-bounds write in jfs_readdir() with multibyte names syzbot
0 siblings, 1 reply; 2+ messages in thread
From: syzbot @ 2026-10-05 15:12 UTC (permalink / raw)
To: linux-kernel, syzkaller-bugs
Hello,
syzbot found the following issue on:
HEAD commit: a90ee4305c4a Linux 7.3-rc6
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output: https://syzkaller.appspot.com/x/log.txt?x=1407a835580000
kernel config: https://syzkaller.appspot.com/x/.config?x=341a98f91c13ec9
dashboard link: https://syzkaller.appspot.com/bug?extid=a2748ba908c108e7e525
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1207a835580000
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+a2748ba908c108e7e525@syzkaller.appspotmail.com
loop0: detected capacity change from 0 to 8388608
==================================================================
BUG: KASAN: slab-out-of-bounds in utf32_to_utf8+0x24d/0x3d0 fs/nls/nls_base.c:111
Write of size 1 at addr ffff888039ad7000 by task syz-executor304/5946
CPU: 1 UID: 0 PID: 5946 Comm: syz-executor304 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/16/2026
Call Trace:
<TASK>
dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
print_address_description+0x55/0x1e0 mm/kasan/report.c:378
print_report+0x58/0x70 mm/kasan/report.c:482
kasan_report+0x117/0x150 mm/kasan/report.c:595
utf32_to_utf8+0x24d/0x3d0 fs/nls/nls_base.c:111
uni2char+0x35/0xa0 fs/nls/nls_utf8.c:21
jfs_strfromUCS_le+0xd2/0x3d0 fs/jfs/jfs_unicode.c:31
jfs_readdir+0x16fd/0x33f0 fs/jfs/jfs_dtree.c:2984
wrap_directory_iterator+0x99/0xe0 fs/readdir.c:67
iterate_dir+0x2f1/0x4e0 fs/readdir.c:110
__do_sys_getdents64 fs/readdir.c:399 [inline]
__se_sys_getdents64+0xf1/0x280 fs/readdir.c:384
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f316a089589
Code: c0 79 93 eb d5 48 8d 7c 1d 00 eb 99 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 d8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fff492e58d8 EFLAGS: 00000246 ORIG_RAX: 00000000000000d9
RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 00007f316a089589
RDX: 0000000000002000 RSI: 00007fff492e5a10 RDI: 0000000000000003
RBP: 00007f316a0e2138 R08: 0000000000000000 R09: 6f6f6c2f7665642f
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000004
R13: 00007fff492e58e0 R14: 00007f316a10dcc0 R15: 0000000000000002
</TASK>
Allocated by task 5946:
kasan_save_stack mm/kasan/common.c:57 [inline]
kasan_save_track+0x3e/0x80 mm/kasan/common.c:78
poison_kmalloc_redzone mm/kasan/common.c:409 [inline]
__kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:426
kasan_kmalloc include/linux/kasan.h:263 [inline]
__kmalloc_cache_noprof+0x3d5/0x680 mm/slub.c:5563
_kmalloc_noprof include/linux/slab.h:991 [inline]
jfs_readdir+0x1169/0x33f0 fs/jfs/jfs_dtree.c:2887
wrap_directory_iterator+0x99/0xe0 fs/readdir.c:67
iterate_dir+0x2f1/0x4e0 fs/readdir.c:110
__do_sys_getdents64 fs/readdir.c:399 [inline]
__se_sys_getdents64+0xf1/0x280 fs/readdir.c:384
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
The buggy address belongs to the object at ffff888039ad6000
which belongs to the cache kmalloc-4k of size 4096
The buggy address is located 0 bytes to the right of
allocated 4096-byte region [ffff888039ad6000, ffff888039ad7000)
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x39ad0
head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0
flags: 0x80000000000040(head|node=0|zone=1)
page_type: f5(slab)
raw: 0080000000000040 ffff88813ffbe140 dead000000000100 dead000000000122
raw: 0000000000000000 0000000000040004 00000000f5000000 0000000000000000
head: 0080000000000040 ffff88813ffbe140 dead000000000100 dead000000000122
head: 0000000000000000 0000000000040004 00000000f5000000 0000000000000000
head: 0080000000000003 fffffffffffffe01 00000000ffffffff 00000000ffffffff
head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000008
page dumped because: kasan: bad access detected
page_owner tracks the page as allocated
page last allocated via order 3, migratetype Unmovable, gfp_mask 0xd2040(__GFP_IO|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC), pid 4965, tgid 4965 (udevd), ts 54440526702
set_page_owner include/linux/page_owner.h:33 [inline]
post_alloc_hook+0x1f9/0x250 mm/page_alloc.c:1871
prep_new_page mm/page_alloc.c:1879 [inline]
get_page_from_freelist+0x2591/0x2600 mm/page_alloc.c:3943
__alloc_frozen_pages_noprof+0x230/0x5c0 mm/page_alloc.c:5436
alloc_slab_page mm/slub.c:3347 [inline]
allocate_slab+0x7d/0x620 mm/slub.c:3462
new_slab mm/slub.c:3513 [inline]
refill_objects+0x2d8/0x350 mm/slub.c:7418
refill_sheaf mm/slub.c:2885 [inline]
__pcs_replace_empty_main+0x339/0x690 mm/slub.c:4774
alloc_from_pcs mm/slub.c:4850 [inline]
slab_alloc_node mm/slub.c:4984 [inline]
__do_kmalloc_node mm/slub.c:5413 [inline]
__kmalloc_noprof+0x54b/0x790 mm/slub.c:5439
_kmalloc_noprof include/linux/slab.h:995 [inline]
tomoyo_realpath_from_path+0xef/0x640 security/tomoyo/realpath.c:251
tomoyo_get_realpath security/tomoyo/file.c:151 [inline]
tomoyo_path_perm+0x283/0x560 security/tomoyo/file.c:827
security_inode_getattr+0x12b/0x310 security/security.c:1895
vfs_getattr fs/stat.c:259 [inline]
vfs_fstat fs/stat.c:281 [inline]
__do_sys_newfstat fs/stat.c:551 [inline]
__se_sys_newfstat fs/stat.c:546 [inline]
__x64_sys_newfstat+0x133/0x270 fs/stat.c:546
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
page last free pid 4961 tgid 4961 ts 54392098709 stack trace:
reset_page_owner include/linux/page_owner.h:26 [inline]
__free_pages_prepare mm/page_alloc.c:1418 [inline]
__free_frozen_pages+0xf8e/0x1070 mm/page_alloc.c:2962
__slab_free+0x250/0x2a0 mm/slub.c:5823
qlink_free mm/kasan/quarantine.c:163 [inline]
qlist_free_all+0x99/0x100 mm/kasan/quarantine.c:179
kasan_quarantine_reduce+0x148/0x160 mm/kasan/quarantine.c:286
__kasan_slab_alloc+0x22/0x80 mm/kasan/common.c:361
kasan_slab_alloc include/linux/kasan.h:253 [inline]
slab_post_alloc_hook mm/slub.c:4683 [inline]
slab_alloc_node mm/slub.c:4996 [inline]
kmem_cache_alloc_noprof+0x360/0x690 mm/slub.c:5010
alloc_filename fs/namei.c:147 [inline]
do_getname+0x2e/0x250 fs/namei.c:187
class_filename_flags_constructor include/linux/fs.h:2586 [inline]
do_sys_openat2+0xcc/0x200 fs/open.c:1416
do_sys_open fs/open.c:1423 [inline]
__do_sys_openat fs/open.c:1439 [inline]
__se_sys_openat fs/open.c:1434 [inline]
__x64_sys_openat+0x138/0x170 fs/open.c:1434
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Memory state around the buggy address:
ffff888039ad6f00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
ffff888039ad6f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
>ffff888039ad7000: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
^
ffff888039ad7080: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
ffff888039ad7100: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
==================================================================
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 2+ messages in thread* Forwarded: [PATCH] jfs: fix slab-out-of-bounds write in jfs_readdir() with multibyte names 2026-10-05 15:12 [syzbot] KASAN: slab-out-of-bounds Write in utf32_to_utf8 syzbot @ 2026-10-06 5:53 ` syzbot 0 siblings, 0 replies; 2+ messages in thread From: syzbot @ 2026-10-06 5:53 UTC (permalink / raw) To: linux-kernel, syzkaller-bugs For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: [PATCH] jfs: fix slab-out-of-bounds write in jfs_readdir() with multibyte names Author: kartikey406@gmail.com #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master syzbot reported a KASAN slab-out-of-bounds write in utf32_to_utf8(), reached via jfs_strfromUCS_le() from jfs_readdir() while handling getdents64() on a crafted JFS image. jfs_readdir() converts on-disk UTF-16 directory entry names into dirent_buf, a PAGE_SIZE buffer. Before converting an entry, it checks that the name fits by assuming one output byte per UTF-16 unit: jfs_dirent + d->namlen + 1 > dirent_buf + PAGE_SIZE With iocharset=utf8 a single UTF-16 unit can expand to up to three bytes, so a name can be approved for space it does not have. jfs_strfromUCS_le() makes this worse: it has no destination size and always passes NLS_MAX_CHARSET_SIZE as the output bound to uni2char(), so the converter believes it has room regardless of how much of the buffer is actually left. The conversion then writes past the end of dirent_buf, and the trailing NUL can land one byte out of bounds too. Fix this in two places: - In jfs_readdir(), reserve the worst case of NLS_MAX_CHARSET_SIZE bytes per UTF-16 unit when checking whether an entry fits. - Give jfs_strfromUCS_le() a destination size (tolen) and pass the real remaining space to uni2char() instead of the constant, keeping one byte for the terminating NUL. Clamp the length in the non-codepage path in the same way. Callers pass the distance to the end of dirent_buf. Reported-by: syzbot+a2748ba908c108e7e525@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=a2748ba908c108e7e525 Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com> --- fs/jfs/jfs_dtree.c | 8 +++++--- fs/jfs/jfs_unicode.c | 15 ++++++++++++--- fs/jfs/jfs_unicode.h | 2 +- 3 files changed, 18 insertions(+), 7 deletions(-) diff --git a/fs/jfs/jfs_dtree.c b/fs/jfs/jfs_dtree.c index 8ce6e4458cc2..5ccc90e3c068 100644 --- a/fs/jfs/jfs_dtree.c +++ b/fs/jfs/jfs_dtree.c @@ -2738,6 +2738,7 @@ int jfs_readdir(struct file *file, struct dir_context *ctx) int jfs_dirents; int overflow, fix_page, page_fixed = 0; static int unique_pos = 2; /* If we can't fix broken index */ + char *buf_end; if (ctx->pos == DIREND) return 0; @@ -2892,6 +2893,7 @@ int jfs_readdir(struct file *file, struct dir_context *ctx) return -ENOMEM; } + buf_end = (char *)dirent_buf + PAGE_SIZE; while (1) { jfs_dirent = dirent_buf; jfs_dirents = 0; @@ -2910,7 +2912,7 @@ int jfs_readdir(struct file *file, struct dir_context *ctx) d = (struct ldtentry *) & p->slot[stbl[i]]; - if (((long) jfs_dirent + d->namlen + 1) > + if (((long) jfs_dirent + (long)d->namlen * NLS_MAX_CHARSET_SIZE + 1) > ((long)dirent_buf + PAGE_SIZE)) { /* DBCS codepages could overrun dirent_buf */ index = i; @@ -2961,7 +2963,7 @@ int jfs_readdir(struct file *file, struct dir_context *ctx) } /* copy the name of head/only segment */ - outlen = jfs_strfromUCS_le(name_ptr, d->name, len, + outlen = jfs_strfromUCS_le(name_ptr, buf_end - name_ptr, d->name, len, codepage); jfs_dirent->name_len = outlen; @@ -2981,7 +2983,7 @@ int jfs_readdir(struct file *file, struct dir_context *ctx) goto skip_one; } len = min(d_namleft, DTSLOTDATALEN); - outlen = jfs_strfromUCS_le(name_ptr, t->name, + outlen = jfs_strfromUCS_le(name_ptr, buf_end - name_ptr , t->name, len, codepage); jfs_dirent->name_len += outlen; diff --git a/fs/jfs/jfs_unicode.c b/fs/jfs/jfs_unicode.c index 0c1e9027245a..bcff7e0031b2 100644 --- a/fs/jfs/jfs_unicode.c +++ b/fs/jfs/jfs_unicode.c @@ -16,27 +16,36 @@ * FUNCTION: Convert little-endian unicode string to character string * */ -int jfs_strfromUCS_le(char *to, const __le16 * from, +int jfs_strfromUCS_le(char *to, int tolen, const __le16 * from, int len, struct nls_table *codepage) { - int i; + int i, room; int outlen = 0; static int warn_again = 5; /* Only warn up to 5 times total */ int warn = !!warn_again; /* once per string */ + if(tolen <= 0) + return 0; + if (codepage) { for (i = 0; (i < len) && from[i]; i++) { int charlen; + room = tolen - outlen - 1; + if(room <= 0) + break; charlen = codepage->uni2char(le16_to_cpu(from[i]), &to[outlen], - NLS_MAX_CHARSET_SIZE); + room); if (charlen > 0) outlen += charlen; else to[outlen++] = '?'; } } else { + if(len > tolen -1) + len = tolen - 1; + for (i = 0; (i < len) && from[i]; i++) { if (unlikely(le16_to_cpu(from[i]) & 0xff00)) { to[i] = '?'; diff --git a/fs/jfs/jfs_unicode.h b/fs/jfs/jfs_unicode.h index b6a78d4aef1b..ea03dd5a0e0c 100644 --- a/fs/jfs/jfs_unicode.h +++ b/fs/jfs/jfs_unicode.h @@ -12,7 +12,7 @@ #include "jfs_types.h" extern int get_UCSname(struct component_name *, struct dentry *); -extern int jfs_strfromUCS_le(char *, const __le16 *, int, struct nls_table *); +extern int jfs_strfromUCS_le(char *, int, const __le16 *, int, struct nls_table *); #define free_UCSname(COMP) kfree((COMP)->name) -- 2.43.0 ^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-06 5:53 UTC | newest] Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- 2026-10-05 15:12 [syzbot] KASAN: slab-out-of-bounds Write in utf32_to_utf8 syzbot 2026-10-06 5:53 ` Forwarded: [PATCH] jfs: fix slab-out-of-bounds write in jfs_readdir() with multibyte names syzbot
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®