exfat: avoid uniname accessing invalid address

In exfat_find_dir_entry, if there doesn't have a TYPE_STREAM(0xc0) entry
before TYPE_EXTEND(0xc1), it will cause kernel panic for the kernel poniter
uniname accessing invalid address

Propogated from OMR1.

Change-Id: Ic8063eafc1c458c96c18a96d58dacd8f33695bb2
Signed-off-by: sunyue5 <sunyue5@motorola.com>
Reviewed-on: https://gerrit.mot.com/1235768
SLTApproved: Slta Waiver
SME-Granted: SME Approvals Granted
Tested-by: Jira Key
Reviewed-by: Yue Sun <sunyue5@lenovo.com>
Reviewed-by: Konstantin Makariev <kmakariev@motorola.com>
Submit-Approved: Jira Key
Signed-off-by: yuedl1 <yuedl1@lenovo.com>
Reviewed-on: https://gerrit.mot.com/1290985
Reviewed-by: Shi-Yong Li <a22381@motorola.com>
Reviewed-by: Zhenxin Xi <xizx@motorola.com>
This commit is contained in:
sunyue5 2018-06-07 09:22:45 +08:00 • committed by Dongliang Yue
commit 41cee75c18

View file

@ -3733,6 +3733,8 @@ s32 fat_find_dir_entry(struct super_block *sb, CHAIN_T *p_dir, UNI_NAME_T *p_uni
if (ext_ep->order > 0x40) {
order = (s32)(ext_ep->order - 0x40);
uniname = p_uniname->name + 13 * (order-1);
} else if (uniname == NULL) {
return -2;
} else {
order = (s32) ext_ep->order;
uniname -= 13;
@ -3861,6 +3863,8 @@ s32 exfat_find_dir_entry(struct super_block *sb, CHAIN_T *p_dir, UNI_NAME_T *p_u
if ((++order) == 2)
uniname = p_uniname->name;
else if (uniname == NULL)
return -2;
else
uniname += 15;