Phillip Lougher
32c114a582
Squashfs: check the inode number is not the invalid value of zero
...
commit 9253c54e01b6505d348afbc02abaa4d9f8a01395 upstream.
Syskiller has produced an out of bounds access in fill_meta_index().
That out of bounds access is ultimately caused because the inode
has an inode number with the invalid value of zero, which was not checked.
The reason this causes the out of bounds access is due to following
sequence of events:
1. Fill_meta_index() is called to allocate (via empty_meta_index())
and fill a metadata index. It however suffers a data read error
and aborts, invalidating the newly returned empty metadata index.
It does this by setting the inode number of the index to zero,
which means unused (zero is not a valid inode number).
2. When fill_meta_index() is subsequently called again on another
read operation, locate_meta_index() returns the previous index
because it matches the inode number of 0. Because this index
has been returned it is expected to have been filled, and because
it hasn't been, an out of bounds access is performed.
This patch adds a sanity check which checks that the inode number
is not zero when the inode is created and returns -EINVAL if it is.
[phillip@squashfs.org.uk: whitespace fix]
Link: https://lkml.kernel.org/r/20240409204723.446925-1-phillip@squashfs.org.uk
Link: https://lkml.kernel.org/r/20240408220206.435788-1-phillip@squashfs.org.uk
Signed-off-by: Phillip Lougher <phillip@squashfs.org.uk>
Reported-by: "Ubisectech Sirius" <bugreport@ubisectech.com>
Closes: https://lore.kernel.org/lkml/87f5c007-b8a5-41ae-8b57-431e924c5915.bugreport@ubisectech.com/
Cc: Christian Brauner <brauner@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Xiangyu Chen <xiangyu.chen@windriver.com>
Signed-off-by: He Zhe <zhe.he@windriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-03-13 12:43:32 +01:00
..
9p
fs/9p: drop inodes immediately on non-.L too
2024-05-17 11:43:53 +02:00
adfs
affs
affs: initialize fsdata in affs_truncate()
2023-02-06 07:52:36 +01:00
afs
afs: Fix directory format encoding struct
2025-03-13 12:42:52 +01:00
autofs
autofs: fix memory leak of waitqueues in autofs_catatonic_mode
2023-09-23 11:00:02 +02:00
befs
bfs
btrfs
btrfs: avoid monopolizing a core when activating a swap file
2025-03-13 12:43:19 +01:00
cachefiles
cachefiles: fix memory leak in cachefiles_add_cache()
2024-03-06 14:36:10 +00:00
ceph
ceph: remove the incorrect Fw reference check when dirtying pages
2024-11-08 16:20:35 +01:00
cifs
cifs: Fix buffer overflow when parsing NFS reparse points
2024-12-14 19:44:21 +01:00
coda
coda: Avoid partial allocation of sig_inputArgs
2023-03-11 16:43:56 +01:00
configfs
cramfs
crypto
debugfs
new helper: lookup_positive_unlocked()
2023-09-23 10:59:40 +02:00
devpts
dlm
dlm: fix plock lookup when using multiple lockspaces
2023-09-23 10:59:55 +02:00
ecryptfs
ecryptfs: Fix buffer size for tag 66 packet
2024-06-16 13:28:32 +02:00
efivarfs
efivarfs: Fix error on non-existent file
2025-01-09 13:23:28 +01:00
efs
erofs
erofs: fix incorrect symlink detection in fast symlink
2025-01-09 13:23:27 +01:00
exportfs
ext2
ext2: fix datatype of block number in ext2_xattr_set2()
2023-09-23 11:00:04 +02:00
ext4
ext4: fix slab-use-after-free in ext4_split_extent_at()
2025-02-01 18:18:53 +01:00
f2fs
f2fs: fix f2fs_bug_on when uninstalling filesystem call f2fs_evict_inode.
2024-12-14 19:44:54 +01:00
fat
fat: fix uninitialized variable
2024-11-08 16:20:47 +01:00
freevxfs
fscache
fuse
fuse: use unsigned type for getxattr/listxattr size truncation
2024-09-12 11:03:51 +02:00
gfs2
gfs2: Truncate address space when flipping GFS2_DIF_JDATA flag
2025-02-01 18:18:52 +01:00
hfs
hfs: Sanity check the root record
2025-02-01 18:18:50 +01:00
hfsplus
hfsplus: don't query the device logical block size multiple times
2024-12-14 19:44:22 +01:00
hostfs
hpfs
hugetlbfs
fs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super
2024-03-06 14:36:10 +00:00
iomap
iomap: Set all uptodate bits for an Uptodate page
2024-03-01 13:13:35 +01:00
isofs
isofs: handle CDs with bad root inode but good Joliet root directory
2024-04-13 12:51:38 +02:00
jbd2
jbd2: flush filesystem device before updating tail sequence
2025-02-01 18:18:44 +01:00
jffs2
jffs2: Fix rtime decompressor
2024-12-14 19:44:56 +01:00
jfs
jfs: add a check to prevent array-index-out-of-bounds in dbAdjTree
2024-12-14 19:44:52 +01:00
kernfs
fs/kernfs/dir: obey S_ISGID
2024-02-23 08:25:03 +01:00
lockd
fs: lockd: avoid possible wrong NULL parameter
2023-09-23 10:59:48 +02:00
minix
nfs
NFS/pnfs: Fix a live lock between recalled layouts and layoutget
2025-01-09 13:23:29 +01:00
nfs_common
nfsd
NFSD: Reset cb_seq_status after NFS4ERR_DELAY
2025-03-13 12:43:01 +01:00
nilfs2
nilfs2: protect access to buffers with no active references
2025-03-13 12:43:18 +01:00
nls
fs/nls: make load_nls() take a const parameter
2023-09-23 10:59:38 +02:00
notify
fanotify: disallow mount/sb marks on kernel internal pseudo fs
2023-07-27 08:37:26 +02:00
ntfs
ocfs2
ocfs2: check dir i_size in ocfs2_find_entry
2025-03-13 12:43:12 +01:00
omfs
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
openpromfs
openpromfs: finish conversion to the new mount API
2024-06-16 13:28:32 +02:00
orangefs
orangefs: fix a oob in orangefs_debug_write
2025-03-13 12:43:13 +01:00
overlayfs
ovl: Filter invalid inodes with missing lookup function
2024-12-14 19:44:43 +01:00
proc
fs/proc: fix softlockup in __read_vmcore (part 2)
2025-02-01 18:18:51 +01:00
pstore
pstore/ram: Fix crash when setting number of cpus to an odd number
2024-02-23 08:24:55 +01:00
qnx4
qnx6
quota
quota: flush quota_release_work upon quota writeback
2024-12-14 19:44:42 +01:00
ramfs
reiserfs
reiserfs: Check the return value from __getblk()
2023-09-23 10:59:40 +02:00
romfs
squashfs
Squashfs: check the inode number is not the invalid value of zero
2025-03-13 12:43:32 +01:00
sysfs
fs: sysfs: Fix reference leak in sysfs_break_active_protection()
2024-05-02 16:18:32 +02:00
sysv
sysv: don't call sb_bread() with pointers_lock held
2024-04-13 12:51:38 +02:00
tracefs
tracefs: Add missing lockdown check to tracefs_create_dir()
2023-09-23 11:00:06 +02:00
ubifs
ubifs: skip dumping tnc tree when zroot is null
2025-03-13 12:42:59 +01:00
udf
udf: Fix use of check_add_overflow() with mixed type arguments
2025-03-13 12:42:51 +01:00
ufs
unicode
Revert "unicode: Don't special case ignorable code points"
2024-12-14 19:44:55 +01:00
verity
fsverity: skip PKCS#7 parser when keyring is empty
2023-09-23 10:59:55 +02:00
xfs
xfs: don't drop errno values when we fail to ficlone the entire range
2024-12-19 18:05:03 +01:00
aio.c
fs/aio: Check IOCB_AIO_RW before the struct aio_kiocb conversion
2024-04-13 12:51:29 +02:00
anon_inodes.c
attr.c
attr: block mode changes of symlinks
2023-09-23 11:00:06 +02:00
bad_inode.c
binfmt_aout.c
binfmt_elf.c
binfmt_elf_fdpic.c
fs: binfmt_elf_efpic: don't use missing interpreter's properties
2024-09-04 13:14:54 +02:00
binfmt_em86.c
binfmt_flat.c
binfmt_flat: Fix integer overflow bug on 32 bit systems
2025-03-13 12:43:07 +01:00
binfmt_misc.c
binfmt_misc: cleanup on filesystem umount
2024-09-04 13:14:53 +02:00
binfmt_script.c
block_dev.c
block: Don't invalidate pagecache for invalid falloc modes
2024-01-08 11:29:48 +01:00
buffer.c
char_dev.c
compat.c
compat_binfmt_elf.c
compat_ioctl.c
lsm: new security_file_ioctl_compat() hook
2024-02-23 08:25:15 +01:00
coredump.c
d_path.c
dax.c
dcache.c
fs: better handle deep ancestor chains in is_subdir()
2024-07-27 10:38:32 +02:00
dcookies.c
direct-io.c
drop_caches.c
eventfd.c
eventfd: prevent underflow for eventfd semaphores
2023-09-23 10:59:40 +02:00
eventpoll.c
epoll: Add synchronous wakeup support for ep_poll_callback
2025-01-09 13:23:32 +01:00
exec.c
parisc: Fix stack start for ADDR_NO_RANDOMIZE personality
2024-11-08 16:20:40 +01:00
fcntl.c
fs: Fix file_set_fowner LSM hook inconsistencies
2024-11-08 16:20:34 +01:00
fhandle.c
do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak
2024-03-26 18:22:13 -04:00
file.c
fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE
2024-09-04 13:14:50 +02:00
file_table.c
filesystems.c
fs-writeback.c
writeback: fix call of incorrect macro
2023-05-17 11:35:58 +02:00
fs_context.c
fs: avoid empty option when generating legacy mount string
2023-07-27 08:37:25 +02:00
fs_parser.c
fs_pin.c
fs_struct.c
fs_types.c
fsopen.c
inode.c
vfs: fix race between evice_inodes() and find_inode()&iput()
2024-11-08 16:20:34 +01:00
internal.h
fs: Establish locking order for unrelated directories
2023-07-27 08:37:26 +02:00
io_uring.c
io_uring: fail NOP if non-zero op flags is passed in
2024-06-16 13:28:48 +02:00
ioctl.c
Kconfig
Kconfig.binfmt
libfs.c
locks.c
filelock: Correct the filelock owner in fcntl_setlk/fcntl_setlk64
2024-09-04 13:15:02 +02:00
Makefile
mbcache.c
mount.h
mpage.c
namei.c
fs: move S_ISGID stripping into the vfs_*() helpers
2024-02-23 08:24:49 +01:00
namespace.c
mount: handle OOM on mnt_warn_timestamp_expiry
2024-11-08 16:20:26 +01:00
no-block.c
nsfs.c
open.c
ftruncate: pass a signed offset
2024-07-05 09:08:31 +02:00
pipe.c
pnode.c
pnode.h
posix_acl.c
proc_namespace.c
read_write.c
readdir.c
select.c
fs/select: rework stack allocation hack for clang
2024-03-26 18:22:13 -04:00
seq_file.c
signalfd.c
splice.c
stack.c
stat.c
statfs.c
statfs: enforce statfs[64] structure initialization
2023-05-30 12:44:07 +01:00
super.c
fs: explicitly unregister per-superblock BDIs
2024-11-08 16:20:26 +01:00
sync.c
ovl: skip overlayfs superblocks at global sync
2023-12-08 08:44:27 +01:00
timerfd.c
userfaultfd.c
utimes.c
xattr.c