From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from canpmsgout09.his.huawei.com (canpmsgout09.his.huawei.com [113.46.200.224]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 988DC41F5CE for ; Thu, 16 Jul 2026 13:32:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.224 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784208763; cv=none; b=Wr8TZ6Xd/dpVGxZjuBW3QkuSDBYdl3SFMtHiqEREZAwRfokMXjO7eJt/d9bNgo4Y2VZb09XrM33ao524s58o8bCar/ZRAAAngvb+VVU5z+3tl5TtrDzxSGtQuyfJ7EbJYL+r/xYzscRSikPYDMhuxut1AN3Pw3cx711//FALT4E= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784208763; c=relaxed/simple; bh=9h1Wi+8shQ9mFAyKqx1EW5sSohkRWO9lnPbhTAB6yCs=; h=Subject:To:CC:References:From:Message-ID:Date:MIME-Version: In-Reply-To:Content-Type; b=mG0lMBYvZfZ2WMq1nr7hZlI3IhLMYY0qHe/lDQeMjBevX01MmSR5FVJGJAlBlMmf0md5YqY55vCmtzdwmShNLmF2HxNKiHZmywbRh7ijKEtE9fMXjmXubgvtMtVezuKqInRCwTXInnsKsKVoPUnrerBM5VW9ztabTm6hAK1ygSg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=SjZSTtEH; arc=none smtp.client-ip=113.46.200.224 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="SjZSTtEH" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=cCvILdSAgwmlg/eLofeXJc1ZZ/ixw70JDPAUvBmUMAI=; b=SjZSTtEHUVM18FE3ZHbuJEFG+hdTo975GDZSPHolKiq9hJr4ZQgCSzAe0u2Rub9X6DXSGf0kJ SKa2Ap6l06LYrAggYzWcvVAbHYlaicFSZ/02rAu5F3hspaflfedTDM/ZuwUbWaGyUcBbxVDoV6L ep48cjna5eVkOJG5sI4IV5U= Received: from mail.maildlp.com (unknown [172.19.163.214]) by canpmsgout09.his.huawei.com (SkyGuard) with ESMTPS id 4h1DJ84mlYz1cyTS; Thu, 16 Jul 2026 21:23:20 +0800 (CST) Received: from whupemo200011.china.huawei.com (unknown [7.152.185.179]) by mail.maildlp.com (Postfix) with ESMTPS id 491814056C; Thu, 16 Jul 2026 21:32:38 +0800 (CST) Received: from [10.174.178.46] (10.174.178.46) by whupemo200011.china.huawei.com (7.152.185.179) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Thu, 16 Jul 2026 21:32:37 +0800 Subject: Re: [PATCH v2] squashfs: Add dictionary size range check to prevent shift-out-of-bounds To: Ran Hongyun , CC: , , References: <20260713115525.2661734-1-ranhongyun1@huawei.com> From: Zhihao Cheng Message-ID: <92aa853b-2b56-8716-2993-47daab4fdc6c@huawei.com> Date: Thu, 16 Jul 2026 21:32:36 +0800 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:68.0) Gecko/20100101 Thunderbird/68.5.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 In-Reply-To: <20260713115525.2661734-1-ranhongyun1@huawei.com> Content-Type: text/plain; charset="gbk"; format=flowed Content-Transfer-Encoding: 8bit X-ClientProxiedBy: kwepems100001.china.huawei.com (7.221.188.238) To whupemo200011.china.huawei.com (7.152.185.179) ÔÚ 2026/7/13 19:55, Ran Hongyun дµÀ: > When an abnormal SquashFS image (COMP_OPTS flag is 1 but dictionary size > is 0) is mounted, and performs shift operations using dictionarysize, the > shift exponent is -1, causing a shift-out-of-bounds. > > Detail as below: > squashfs_comp_opts(msblk, buffer, length) > squashfs_xz_comp_opts() > if (comp_opts) > n = ffs(opts->dict_size) - 1;<----opts->dict_size=0, n=-1 > if (opts->dict_size != (1 << n) && opts->dict_size != > (1 << n) + (1 << (n + 1))) <----shift-out-of-bounds > > Fix it by adding a dictionary size range check before the shift operation. > > Fixes: ff750311d30a ("Squashfs: add compression options support to xz decompressor") > Signed-off-by: Ran Hongyun > --- > fs/squashfs/xz_wrapper.c | 6 +++--- > 1 file changed, 3 insertions(+), 3 deletions(-) Reviewed-by: Zhihao Cheng > > diff --git a/fs/squashfs/xz_wrapper.c b/fs/squashfs/xz_wrapper.c > index 6c49481a2f8c..7d54cd524d6d 100644 > --- a/fs/squashfs/xz_wrapper.c > +++ b/fs/squashfs/xz_wrapper.c > @@ -57,10 +57,10 @@ static void *squashfs_xz_comp_opts(struct squashfs_sb_info *msblk, > > opts->dict_size = le32_to_cpu(comp_opts->dictionary_size); > > - /* the dictionary size should be 2^n or 2^n+2^(n+1) */ > + /* the dictionary size should be positive and 2^n or 2^n+2^(n+1) */ > n = ffs(opts->dict_size) - 1; > - if (opts->dict_size != (1 << n) && opts->dict_size != (1 << n) + > - (1 << (n + 1))) { > + if (opts->dict_size <= 0 || (opts->dict_size != (1 << n) && > + opts->dict_size != (1 << n) + (1 << (n + 1)))) { > err = -EIO; > goto out; > } >