Skip to content

Commit 3ec997b

Browse files
bryamzxzjankara
authored andcommitted
udf: validate sparing table length as an entry count, not a byte count
udf_load_sparable_map() accepts a sparing table when sizeof(*st) + le16_to_cpu(st->reallocationTableLen) > sb->s_blocksize is false, i.e. it treats reallocationTableLen as a number of BYTES that must fit in the block. But the table is walked as an array of 8-byte sparingEntry elements: for (i = 0; i < le16_to_cpu(st->reallocationTableLen); i++) { struct sparingEntry *entry = &st->mapEntry[i]; ... entry->origLocation ... } in udf_get_pblock_spar15() and udf_relocate_blocks(). A reallocationTableLen of N therefore passes the check whenever sizeof(*st) + N <= blocksize, yet the consumers index sizeof(*st) + N * sizeof(struct sparingEntry) bytes -- up to ~8x the block. On a crafted UDF image this is an out-of-bounds read in udf_get_pblock_spar15(); udf_relocate_blocks() additionally feeds the same length to udf_update_tag(), whose crc_itu_t() reads far past the block, and its memmove() through st->mapEntry[] is an out-of-bounds write. Validate reallocationTableLen as the entry count it is, with struct_size(). Fixes: 1df2ae3 ("udf: Fortify loading of sparing table") Cc: stable@vger.kernel.org Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me> Link: https://patch.msgid.link/20260612-b4-disp-91780c4e-v1-1-f15112ff6882@proton.me Signed-off-by: Jan Kara <jack@suse.cz>
1 parent 5fa1d6a commit 3ec997b

1 file changed

Lines changed: 2 additions & 1 deletion

File tree

fs/udf/super.c

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1418,7 +1418,8 @@ static int udf_load_sparable_map(struct super_block *sb,
14181418
if (ident != 0 ||
14191419
strncmp(st->sparingIdent.ident, UDF_ID_SPARING,
14201420
strlen(UDF_ID_SPARING)) ||
1421-
sizeof(*st) + le16_to_cpu(st->reallocationTableLen) >
1421+
struct_size(st, mapEntry,
1422+
le16_to_cpu(st->reallocationTableLen)) >
14221423
sb->s_blocksize) {
14231424
brelse(bh);
14241425
continue;

0 commit comments

Comments
 (0)