android_kernel_motorola_sm6375/fs
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Acs, Jakub 14da7dbecb ext4: fix OOB read when checking dotdot dir
[ Upstream commit d5e206778e96e8667d3bde695ad372c296dc9353 ]

Mounting a corrupted filesystem with directory which contains '.' dir
entry with rec_len == block size results in out-of-bounds read (later
on, when the corrupted directory is removed).

ext4_empty_dir() assumes every ext4 directory contains at least '.'
and '..' as directory entries in the first data block. It first loads
the '.' dir entry, performs sanity checks by calling ext4_check_dir_entry()
and then uses its rec_len member to compute the location of '..' dir
entry (in ext4_next_entry). It assumes the '..' dir entry fits into the
same data block.

If the rec_len of '.' is precisely one block (4KB), it slips through the
sanity checks (it is considered the last directory entry in the data
block) and leaves "struct ext4_dir_entry_2 *de" point exactly past the
memory slot allocated to the data block. The following call to
ext4_check_dir_entry() on new value of de then dereferences this pointer
which results in out-of-bounds mem access.

Fix this by extending __ext4_check_dir_entry() to check for '.' dir
entries that reach the end of data block. Make sure to ignore the phony
dir entries for checksum (by checking name_len for non-zero).

Note: This is reported by KASAN as use-after-free in case another
structure was recently freed from the slot past the bound, but it is
really an OOB read.

This issue was found by syzkaller tool.

Call Trace:
[   38.594108] BUG: KASAN: slab-use-after-free in __ext4_check_dir_entry+0x67e/0x710
[   38.594649] Read of size 2 at addr ffff88802b41a004 by task syz-executor/5375
[   38.595158]
[   38.595288] CPU: 0 UID: 0 PID: 5375 Comm: syz-executor Not tainted 6.14.0-rc7 #1
[   38.595298] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
[   38.595304] Call Trace:
[   38.595308]  <TASK>
[   38.595311]  dump_stack_lvl+0xa7/0xd0
[   38.595325]  print_address_description.constprop.0+0x2c/0x3f0
[   38.595339]  ? __ext4_check_dir_entry+0x67e/0x710
[   38.595349]  print_report+0xaa/0x250
[   38.595359]  ? __ext4_check_dir_entry+0x67e/0x710
[   38.595368]  ? kasan_addr_to_slab+0x9/0x90
[   38.595378]  kasan_report+0xab/0xe0
[   38.595389]  ? __ext4_check_dir_entry+0x67e/0x710
[   38.595400]  __ext4_check_dir_entry+0x67e/0x710
[   38.595410]  ext4_empty_dir+0x465/0x990
[   38.595421]  ? __pfx_ext4_empty_dir+0x10/0x10
[   38.595432]  ext4_rmdir.part.0+0x29a/0xd10
[   38.595441]  ? __dquot_initialize+0x2a7/0xbf0
[   38.595455]  ? __pfx_ext4_rmdir.part.0+0x10/0x10
[   38.595464]  ? __pfx___dquot_initialize+0x10/0x10
[   38.595478]  ? down_write+0xdb/0x140
[   38.595487]  ? __pfx_down_write+0x10/0x10
[   38.595497]  ext4_rmdir+0xee/0x140
[   38.595506]  vfs_rmdir+0x209/0x670
[   38.595517]  ? lookup_one_qstr_excl+0x3b/0x190
[   38.595529]  do_rmdir+0x363/0x3c0
[   38.595537]  ? __pfx_do_rmdir+0x10/0x10
[   38.595544]  ? strncpy_from_user+0x1ff/0x2e0
[   38.595561]  __x64_sys_unlinkat+0xf0/0x130
[   38.595570]  do_syscall_64+0x5b/0x180
[   38.595583]  entry_SYSCALL_64_after_hwframe+0x76/0x7e

Fixes: ac27a0ec11 ("[PATCH] ext4: initial copy of files from ext3")
Signed-off-by: Jakub Acs <acsjakub@amazon.de>
Cc: Theodore Ts'o <tytso@mit.edu>
Cc: Andreas Dilger <adilger.kernel@dilger.ca>
Cc: linux-ext4@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Cc: Mahmoud Adam <mngyadam@amazon.com>
Cc: stable@vger.kernel.org
Cc: security@kernel.org
Link: https://patch.msgid.link/b3ae36a6794c4a01944c7d70b403db5b@amazon.de
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-05-02 07:39:24 +02:00
..
9p fs/9p: drop inodes immediately on non-.L too 2024-05-17 11:43:53 +02:00
adfs
affs affs: don't write overlarge OFS data block size fields 2025-04-10 14:29:42 +02:00
afs afs: Fix directory format encoding struct 2025-03-13 12:42:52 +01:00
autofs autofs: fix memory leak of waitqueues in autofs_catatonic_mode 2023-09-23 11:00:02 +02:00
befs
bfs
btrfs btrfs: correctly escape subvol in btrfs_show_options() 2025-05-02 07:39:20 +02:00
cachefiles cachefiles: fix memory leak in cachefiles_add_cache() 2024-03-06 14:36:10 +00:00
ceph ceph: remove the incorrect Fw reference check when dirtying pages 2024-11-08 16:20:35 +01:00
cifs cifs: Fix buffer overflow when parsing NFS reparse points 2024-12-14 19:44:21 +01:00
coda
configfs
cramfs
crypto
debugfs new helper: lookup_positive_unlocked() 2023-09-23 10:59:40 +02:00
devpts
dlm dlm: fix plock lookup when using multiple lockspaces 2023-09-23 10:59:55 +02:00
ecryptfs ecryptfs: Fix buffer size for tag 66 packet 2024-06-16 13:28:32 +02:00
efivarfs efivarfs: Fix error on non-existent file 2025-01-09 13:23:28 +01:00
efs
erofs erofs: fix incorrect symlink detection in fast symlink 2025-01-09 13:23:27 +01:00
exportfs
ext2 ext2: fix datatype of block number in ext2_xattr_set2() 2023-09-23 11:00:04 +02:00
ext4 ext4: fix OOB read when checking dotdot dir 2025-05-02 07:39:24 +02:00
f2fs f2fs: fix f2fs_bug_on when uninstalling filesystem call f2fs_evict_inode. 2024-12-14 19:44:54 +01:00
fat fat: fix uninitialized variable 2024-11-08 16:20:47 +01:00
freevxfs
fscache
fuse virtiofs: add filesystem context source name check 2025-05-02 07:39:21 +02:00
gfs2 gfs2: Truncate address space when flipping GFS2_DIF_JDATA flag 2025-02-01 18:18:52 +01:00
hfs hfs/hfsplus: fix slab-out-of-bounds in hfs_bnode_read_key 2025-05-02 07:39:20 +02:00
hfsplus hfs/hfsplus: fix slab-out-of-bounds in hfs_bnode_read_key 2025-05-02 07:39:20 +02:00
hostfs
hpfs
hugetlbfs fs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super 2024-03-06 14:36:10 +00:00
iomap iomap: Set all uptodate bits for an Uptodate page 2024-03-01 13:13:35 +01:00
isofs isofs: Prevent the use of too small fid 2025-05-02 07:39:20 +02:00
jbd2 jbd2: remove wrong sb->s_sequence check 2025-05-02 07:39:15 +02:00
jffs2 jffs2: Fix rtime decompressor 2024-12-14 19:44:56 +01:00
jfs jfs: add sanity check for agwidth in dbMount 2025-05-02 07:39:10 +02:00
kernfs fs/kernfs/dir: obey S_ISGID 2024-02-23 08:25:03 +01:00
lockd fs: lockd: avoid possible wrong NULL parameter 2023-09-23 10:59:48 +02:00
minix
nfs nfs: add missing selections of CONFIG_CRC32 2025-05-02 07:39:20 +02:00
nfs_common
nfsd nfs: add missing selections of CONFIG_CRC32 2025-05-02 07:39:20 +02:00
nilfs2 nilfs2: protect access to buffers with no active references 2025-03-13 12:43:18 +01:00
nls fs/nls: make load_nls() take a const parameter 2023-09-23 10:59:38 +02:00
notify fanotify: disallow mount/sb marks on kernel internal pseudo fs 2023-07-27 08:37:26 +02:00
ntfs
ocfs2 ocfs2: validate l_tree_depth to avoid out-of-bounds access 2025-04-10 14:29:41 +02:00
omfs treewide: Remove uninitialized_var() usage 2023-06-09 10:29:01 +02:00
openpromfs openpromfs: finish conversion to the new mount API 2024-06-16 13:28:32 +02:00
orangefs orangefs: fix a oob in orangefs_debug_write 2025-03-13 12:43:13 +01:00
overlayfs ovl: Filter invalid inodes with missing lookup function 2024-12-14 19:44:43 +01:00
proc fs/procfs: fix the comment above proc_pid_wchan() 2025-04-10 14:29:42 +02:00
pstore pstore/ram: Fix crash when setting number of cpus to an odd number 2024-02-23 08:24:55 +01:00
qnx4
qnx6
quota quota: flush quota_release_work upon quota writeback 2024-12-14 19:44:42 +01:00
ramfs
reiserfs reiserfs: Check the return value from __getblk() 2023-09-23 10:59:40 +02:00
romfs
squashfs Squashfs: check the inode number is not the invalid value of zero 2025-03-13 12:43:32 +01:00
sysfs fs: sysfs: Fix reference leak in sysfs_break_active_protection() 2024-05-02 16:18:32 +02:00
sysv sysv: don't call sb_bread() with pointers_lock held 2024-04-13 12:51:38 +02:00
tracefs tracefs: Add missing lockdown check to tracefs_create_dir() 2023-09-23 11:00:06 +02:00
ubifs ubifs: skip dumping tnc tree when zroot is null 2025-03-13 12:42:59 +01:00
udf udf: Fix use of check_add_overflow() with mixed type arguments 2025-03-13 12:42:51 +01:00
ufs
unicode Revert "unicode: Don't special case ignorable code points" 2024-12-14 19:44:55 +01:00
verity fsverity: skip PKCS#7 parser when keyring is empty 2023-09-23 10:59:55 +02:00
xfs xfs: don't drop errno values when we fail to ficlone the entire range 2024-12-19 18:05:03 +01:00
aio.c fs/aio: Check IOCB_AIO_RW before the struct aio_kiocb conversion 2024-04-13 12:51:29 +02:00
anon_inodes.c
attr.c attr: block mode changes of symlinks 2023-09-23 11:00:06 +02:00
bad_inode.c
binfmt_aout.c
binfmt_elf.c
binfmt_elf_fdpic.c fs: binfmt_elf_efpic: don't use missing interpreter's properties 2024-09-04 13:14:54 +02:00
binfmt_em86.c
binfmt_flat.c binfmt_flat: Fix integer overflow bug on 32 bit systems 2025-03-13 12:43:07 +01:00
binfmt_misc.c binfmt_misc: cleanup on filesystem umount 2024-09-04 13:14:53 +02:00
binfmt_script.c
block_dev.c block: Don't invalidate pagecache for invalid falloc modes 2024-01-08 11:29:48 +01:00
buffer.c
char_dev.c
compat.c
compat_binfmt_elf.c
compat_ioctl.c lsm: new security_file_ioctl_compat() hook 2024-02-23 08:25:15 +01:00
coredump.c
d_path.c
dax.c
dcache.c fs: better handle deep ancestor chains in is_subdir() 2024-07-27 10:38:32 +02:00
dcookies.c
direct-io.c
drop_caches.c
eventfd.c eventfd: prevent underflow for eventfd semaphores 2023-09-23 10:59:40 +02:00
eventpoll.c epoll: Add synchronous wakeup support for ep_poll_callback 2025-01-09 13:23:32 +01:00
exec.c parisc: Fix stack start for ADDR_NO_RANDOMIZE personality 2024-11-08 16:20:40 +01:00
fcntl.c fs: Fix file_set_fowner LSM hook inconsistencies 2024-11-08 16:20:34 +01:00
fhandle.c do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak 2024-03-26 18:22:13 -04:00
file.c fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE 2024-09-04 13:14:50 +02:00
file_table.c
filesystems.c
fs-writeback.c writeback: fix call of incorrect macro 2023-05-17 11:35:58 +02:00
fs_context.c fs: avoid empty option when generating legacy mount string 2023-07-27 08:37:25 +02:00
fs_parser.c
fs_pin.c
fs_struct.c
fs_types.c
fsopen.c
inode.c vfs: fix race between evice_inodes() and find_inode()&iput() 2024-11-08 16:20:34 +01:00
internal.h fs: Establish locking order for unrelated directories 2023-07-27 08:37:26 +02:00
io_uring.c io_uring: fail NOP if non-zero op flags is passed in 2024-06-16 13:28:48 +02:00
ioctl.c
Kconfig nfs: add missing selections of CONFIG_CRC32 2025-05-02 07:39:20 +02:00
Kconfig.binfmt
libfs.c
locks.c filelock: Correct the filelock owner in fcntl_setlk/fcntl_setlk64 2024-09-04 13:15:02 +02:00
Makefile
mbcache.c
mount.h
mpage.c
namei.c fuse: don't truncate cached, mutated symlink 2025-04-10 14:29:36 +02:00
namespace.c mount: handle OOM on mnt_warn_timestamp_expiry 2024-11-08 16:20:26 +01:00
no-block.c
nsfs.c
open.c ftruncate: pass a signed offset 2024-07-05 09:08:31 +02:00
pipe.c
pnode.c
pnode.h
posix_acl.c
proc_namespace.c
read_write.c
readdir.c
select.c fs/select: rework stack allocation hack for clang 2024-03-26 18:22:13 -04:00
seq_file.c
signalfd.c
splice.c
stack.c
stat.c
statfs.c statfs: enforce statfs[64] structure initialization 2023-05-30 12:44:07 +01:00
super.c fs: explicitly unregister per-superblock BDIs 2024-11-08 16:20:26 +01:00
sync.c ovl: skip overlayfs superblocks at global sync 2023-12-08 08:44:27 +01:00
timerfd.c
userfaultfd.c
utimes.c
xattr.c