Thadeu Lima de Souza Cascardo
f57725bcc5
hfsplus: don't query the device logical block size multiple times
[ Upstream commit 1c82587cb57687de3f18ab4b98a8850c789bedcf ]
Devices block sizes may change. One of these cases is a loop device by
using ioctl LOOP_SET_BLOCK_SIZE.
While this may cause other issues like IO being rejected, in the case of
hfsplus, it will allocate a block by using that size and potentially write
out-of-bounds when hfsplus_read_wrapper calls hfsplus_submit_bio and the
latter function reads a different io_size.
Using a new min_io_size initally set to sb_min_blocksize works for the
purposes of the original fix, since it will be set to the max between
HFSPLUS_SECTOR_SIZE and the first seen logical block size. We still use the
max between HFSPLUS_SECTOR_SIZE and min_io_size in case the latter is not
initialized.
Tested by mounting an hfsplus filesystem with loop block sizes 512, 1024
and 4096.
The produced KASAN report before the fix looks like this:
[ 419.944641] ==================================================================
[ 419.945655] BUG: KASAN: slab-use-after-free in hfsplus_read_wrapper+0x659/0xa0a
[ 419.946703] Read of size 2 at addr ffff88800721fc00 by task repro/10678
[ 419.947612]
[ 419.947846] CPU: 0 UID: 0 PID: 10678 Comm: repro Not tainted 6.12.0-rc5-00008-gdf56e0f2f3ca #84
[ 419.949007] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014
[ 419.950035] Call Trace:
[ 419.950384] <TASK>
[ 419.950676] dump_stack_lvl+0x57/0x78
[ 419.951212] ? hfsplus_read_wrapper+0x659/0xa0a
[ 419.951830] print_report+0x14c/0x49e
[ 419.952361] ? __virt_addr_valid+0x267/0x278
[ 419.952979] ? kmem_cache_debug_flags+0xc/0x1d
[ 419.953561] ? hfsplus_read_wrapper+0x659/0xa0a
[ 419.954231] kasan_report+0x89/0xb0
[ 419.954748] ? hfsplus_read_wrapper+0x659/0xa0a
[ 419.955367] hfsplus_read_wrapper+0x659/0xa0a
[ 419.955948] ? __pfx_hfsplus_read_wrapper+0x10/0x10
[ 419.956618] ? do_raw_spin_unlock+0x59/0x1a9
[ 419.957214] ? _raw_spin_unlock+0x1a/0x2e
[ 419.957772] hfsplus_fill_super+0x348/0x1590
[ 419.958355] ? hlock_class+0x4c/0x109
[ 419.958867] ? __pfx_hfsplus_fill_super+0x10/0x10
[ 419.959499] ? __pfx_string+0x10/0x10
[ 419.960006] ? lock_acquire+0x3e2/0x454
[ 419.960532] ? bdev_name.constprop.0+0xce/0x243
[ 419.961129] ? __pfx_bdev_name.constprop.0+0x10/0x10
[ 419.961799] ? pointer+0x3f0/0x62f
[ 419.962277] ? __pfx_pointer+0x10/0x10
[ 419.962761] ? vsnprintf+0x6c4/0xfba
[ 419.963178] ? __pfx_vsnprintf+0x10/0x10
[ 419.963621] ? setup_bdev_super+0x376/0x3b3
[ 419.964029] ? snprintf+0x9d/0xd2
[ 419.964344] ? __pfx_snprintf+0x10/0x10
[ 419.964675] ? lock_acquired+0x45c/0x5e9
[ 419.965016] ? set_blocksize+0x139/0x1c1
[ 419.965381] ? sb_set_blocksize+0x6d/0xae
[ 419.965742] ? __pfx_hfsplus_fill_super+0x10/0x10
[ 419.966179] mount_bdev+0x12f/0x1bf
[ 419.966512] ? __pfx_mount_bdev+0x10/0x10
[ 419.966886] ? vfs_parse_fs_string+0xce/0x111
[ 419.967293] ? __pfx_vfs_parse_fs_string+0x10/0x10
[ 419.967702] ? __pfx_hfsplus_mount+0x10/0x10
[ 419.968073] legacy_get_tree+0x104/0x178
[ 419.968414] vfs_get_tree+0x86/0x296
[ 419.968751] path_mount+0xba3/0xd0b
[ 419.969157] ? __pfx_path_mount+0x10/0x10
[ 419.969594] ? kmem_cache_free+0x1e2/0x260
[ 419.970311] do_mount+0x99/0xe0
[ 419.970630] ? __pfx_do_mount+0x10/0x10
[ 419.971008] __do_sys_mount+0x199/0x1c9
[ 419.971397] do_syscall_64+0xd0/0x135
[ 419.971761] entry_SYSCALL_64_after_hwframe+0x76/0x7e
[ 419.972233] RIP: 0033:0x7c3cb812972e
[ 419.972564] Code: 48 8b 0d f5 46 0d 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d c2 46 0d 00 f7 d8 64 89 01 48
[ 419.974371] RSP: 002b:00007ffe30632548 EFLAGS: 00000286 ORIG_RAX: 00000000000000a5
[ 419.975048] RAX: ffffffffffffffda RBX: 00007ffe306328d8 RCX: 00007c3cb812972e
[ 419.975701] RDX: 0000000020000000 RSI: 0000000020000c80 RDI: 00007ffe306325d0
[ 419.976363] RBP: 00007ffe30632720 R08: 00007ffe30632610 R09: 0000000000000000
[ 419.977034] R10: 0000000000200008 R11: 0000000000000286 R12: 0000000000000000
[ 419.977713] R13: 00007ffe306328e8 R14: 00005a0eb298bc68 R15: 00007c3cb8356000
[ 419.978375] </TASK>
[ 419.978589]
Fixes: 6596528e39 ("hfsplus: ensure bio requests are not smaller than the hardware sectors")
Signed-off-by: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
Link: https://lore.kernel.org/r/20241107114109.839253-1-cascardo@igalia.com
Signed-off-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
|
2024-12-14 19:44:22 +01:00 |
| .. |
|
9p
|
fs/9p: drop inodes immediately on non-.L too
|
2024-05-17 11:43:53 +02:00 |
|
adfs
|
|
|
|
affs
|
affs: initialize fsdata in affs_truncate()
|
2023-02-06 07:52:36 +01:00 |
|
afs
|
afs: Don't cross .backup mountpoint from backup volume
|
2024-06-16 13:28:48 +02:00 |
|
autofs
|
autofs: fix memory leak of waitqueues in autofs_catatonic_mode
|
2023-09-23 11:00:02 +02:00 |
|
befs
|
|
|
|
bfs
|
|
|
|
btrfs
|
btrfs: reinitialize delayed ref list after deleting it from the list
|
2024-11-17 14:58:51 +01:00 |
|
cachefiles
|
cachefiles: fix memory leak in cachefiles_add_cache()
|
2024-03-06 14:36:10 +00:00 |
|
ceph
|
ceph: remove the incorrect Fw reference check when dirtying pages
|
2024-11-08 16:20:35 +01:00 |
|
cifs
|
cifs: Fix buffer overflow when parsing NFS reparse points
|
2024-12-14 19:44:21 +01:00 |
|
coda
|
coda: Avoid partial allocation of sig_inputArgs
|
2023-03-11 16:43:56 +01:00 |
|
configfs
|
configfs: fix possible memory leak in configfs_create_dir()
|
2023-01-18 11:41:09 +01:00 |
|
cramfs
|
|
|
|
crypto
|
|
|
|
debugfs
|
new helper: lookup_positive_unlocked()
|
2023-09-23 10:59:40 +02:00 |
|
devpts
|
|
|
|
dlm
|
dlm: fix plock lookup when using multiple lockspaces
|
2023-09-23 10:59:55 +02:00 |
|
ecryptfs
|
ecryptfs: Fix buffer size for tag 66 packet
|
2024-06-16 13:28:32 +02:00 |
|
efivarfs
|
|
|
|
efs
|
|
|
|
erofs
|
erofs: fix lz4 inplace decompression
|
2024-11-08 16:20:49 +01:00 |
|
exportfs
|
|
|
|
ext2
|
ext2: fix datatype of block number in ext2_xattr_set2()
|
2023-09-23 11:00:04 +02:00 |
|
ext4
|
ext4: nested locking for xattr inode
|
2024-11-08 16:20:44 +01:00 |
|
f2fs
|
f2fs: Require FMODE_WRITE for atomic write ioctls
|
2024-11-08 16:20:36 +01:00 |
|
fat
|
fat: fix uninitialized variable
|
2024-11-08 16:20:47 +01:00 |
|
freevxfs
|
|
|
|
fscache
|
|
|
|
fuse
|
fuse: use unsigned type for getxattr/listxattr size truncation
|
2024-09-12 11:03:51 +02:00 |
|
gfs2
|
gfs2: setattr_chown: Add missing initialization
|
2024-09-04 13:14:54 +02:00 |
|
hfs
|
hfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()
|
2024-08-19 05:33:36 +02:00 |
|
hfsplus
|
hfsplus: don't query the device logical block size multiple times
|
2024-12-14 19:44:22 +01:00 |
|
hostfs
|
|
|
|
hpfs
|
|
|
|
hugetlbfs
|
fs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super
|
2024-03-06 14:36:10 +00:00 |
|
iomap
|
iomap: Set all uptodate bits for an Uptodate page
|
2024-03-01 13:13:35 +01:00 |
|
isofs
|
isofs: handle CDs with bad root inode but good Joliet root directory
|
2024-04-13 12:51:38 +02:00 |
|
jbd2
|
jbd2: stop waiting for space when jbd2_cleanup_journal_tail() returns error
|
2024-11-08 16:20:40 +01:00 |
|
jffs2
|
jffs2: Fix potential illegal address access in jffs2_free_inode
|
2024-07-18 11:40:49 +02:00 |
|
jfs
|
jfs: Fix sanity check in dbMount
|
2024-11-08 16:20:50 +01:00 |
|
kernfs
|
fs/kernfs/dir: obey S_ISGID
|
2024-02-23 08:25:03 +01:00 |
|
lockd
|
fs: lockd: avoid possible wrong NULL parameter
|
2023-09-23 10:59:48 +02:00 |
|
minix
|
|
|
|
nfs
|
nfs: Fix KMSAN warning in decode_getfattr_attrs()
|
2024-11-17 14:58:51 +01:00 |
|
nfs_common
|
|
|
|
nfsd
|
NFSD: Force all NFSv4.2 COPY requests to be synchronous
|
2024-12-14 19:44:21 +01:00 |
|
nilfs2
|
nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint
|
2024-12-14 19:44:19 +01:00 |
|
nls
|
fs/nls: make load_nls() take a const parameter
|
2023-09-23 10:59:38 +02:00 |
|
notify
|
fanotify: disallow mount/sb marks on kernel internal pseudo fs
|
2023-07-27 08:37:26 +02:00 |
|
ntfs
|
ntfs: check overflow when iterating ATTR_RECORDs
|
2022-11-25 17:42:22 +01:00 |
|
ocfs2
|
ocfs2: fix UBSAN warning in ocfs2_verify_volume()
|
2024-12-14 19:44:19 +01:00 |
|
omfs
|
treewide: Remove uninitialized_var() usage
|
2023-06-09 10:29:01 +02:00 |
|
openpromfs
|
openpromfs: finish conversion to the new mount API
|
2024-06-16 13:28:32 +02:00 |
|
orangefs
|
orangefs: fix out-of-bounds fsid access
|
2024-07-18 11:40:49 +02:00 |
|
overlayfs
|
ovl: skip overlayfs superblocks at global sync
|
2023-12-08 08:44:27 +01:00 |
|
proc
|
proc/softirqs: replace seq_printf with seq_put_decimal_ull_width
|
2024-12-14 19:44:21 +01:00 |
|
pstore
|
pstore/ram: Fix crash when setting number of cpus to an odd number
|
2024-02-23 08:24:55 +01:00 |
|
qnx4
|
|
|
|
qnx6
|
|
|
|
quota
|
quota: Remove BUG_ON from dqget()
|
2024-09-04 13:14:54 +02:00 |
|
ramfs
|
|
|
|
reiserfs
|
reiserfs: Check the return value from __getblk()
|
2023-09-23 10:59:40 +02:00 |
|
romfs
|
|
|
|
squashfs
|
Squashfs: sanity check symbolic link size
|
2024-09-12 11:03:55 +02:00 |
|
sysfs
|
fs: sysfs: Fix reference leak in sysfs_break_active_protection()
|
2024-05-02 16:18:32 +02:00 |
|
sysv
|
sysv: don't call sb_bread() with pointers_lock held
|
2024-04-13 12:51:38 +02:00 |
|
tracefs
|
tracefs: Add missing lockdown check to tracefs_create_dir()
|
2023-09-23 11:00:06 +02:00 |
|
ubifs
|
ubifs: Set page uptodate in the correct place
|
2024-04-13 12:51:23 +02:00 |
|
udf
|
udf: fix uninit-value use in udf_get_fileshortad
|
2024-11-08 16:20:50 +01:00 |
|
ufs
|
|
|
|
unicode
|
unicode: Don't special case ignorable code points
|
2024-11-08 16:20:43 +01:00 |
|
verity
|
fsverity: skip PKCS#7 parser when keyring is empty
|
2023-09-23 10:59:55 +02:00 |
|
xfs
|
xfs: verify buffer contents when we skip log replay
|
2023-06-28 10:18:42 +02:00 |
|
aio.c
|
fs/aio: Check IOCB_AIO_RW before the struct aio_kiocb conversion
|
2024-04-13 12:51:29 +02:00 |
|
anon_inodes.c
|
|
|
|
attr.c
|
attr: block mode changes of symlinks
|
2023-09-23 11:00:06 +02:00 |
|
bad_inode.c
|
|
|
|
binfmt_aout.c
|
binfmt: Move install_exec_creds after setup_new_exec to match binfmt_elf
|
2023-01-18 11:41:46 +01:00 |
|
binfmt_elf.c
|
|
|
|
binfmt_elf_fdpic.c
|
fs: binfmt_elf_efpic: don't use missing interpreter's properties
|
2024-09-04 13:14:54 +02:00 |
|
binfmt_em86.c
|
|
|
|
binfmt_flat.c
|
binfmt: Move install_exec_creds after setup_new_exec to match binfmt_elf
|
2023-01-18 11:41:46 +01:00 |
|
binfmt_misc.c
|
binfmt_misc: cleanup on filesystem umount
|
2024-09-04 13:14:53 +02:00 |
|
binfmt_script.c
|
|
|
|
block_dev.c
|
block: Don't invalidate pagecache for invalid falloc modes
|
2024-01-08 11:29:48 +01:00 |
|
buffer.c
|
mm: fs: initialize fsdata passed to write_begin/write_end interface
|
2022-11-25 17:42:22 +01:00 |
|
char_dev.c
|
chardev: fix error handling in cdev_device_add()
|
2023-01-18 11:41:25 +01:00 |
|
compat.c
|
|
|
|
compat_binfmt_elf.c
|
|
|
|
compat_ioctl.c
|
lsm: new security_file_ioctl_compat() hook
|
2024-02-23 08:25:15 +01:00 |
|
coredump.c
|
|
|
|
d_path.c
|
|
|
|
dax.c
|
|
|
|
dcache.c
|
fs: better handle deep ancestor chains in is_subdir()
|
2024-07-27 10:38:32 +02:00 |
|
dcookies.c
|
|
|
|
direct-io.c
|
|
|
|
drop_caches.c
|
|
|
|
eventfd.c
|
eventfd: prevent underflow for eventfd semaphores
|
2023-09-23 10:59:40 +02:00 |
|
eventpoll.c
|
epoll: ep_autoremove_wake_function should use list_del_init_careful
|
2023-06-28 10:18:35 +02:00 |
|
exec.c
|
parisc: Fix stack start for ADDR_NO_RANDOMIZE personality
|
2024-11-08 16:20:40 +01:00 |
|
fcntl.c
|
fs: Fix file_set_fowner LSM hook inconsistencies
|
2024-11-08 16:20:34 +01:00 |
|
fhandle.c
|
do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak
|
2024-03-26 18:22:13 -04:00 |
|
file.c
|
fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE
|
2024-09-04 13:14:50 +02:00 |
|
file_table.c
|
|
|
|
filesystems.c
|
|
|
|
fs-writeback.c
|
writeback: fix call of incorrect macro
|
2023-05-17 11:35:58 +02:00 |
|
fs_context.c
|
fs: avoid empty option when generating legacy mount string
|
2023-07-27 08:37:25 +02:00 |
|
fs_parser.c
|
|
|
|
fs_pin.c
|
|
|
|
fs_struct.c
|
|
|
|
fs_types.c
|
|
|
|
fsopen.c
|
|
|
|
inode.c
|
vfs: fix race between evice_inodes() and find_inode()&iput()
|
2024-11-08 16:20:34 +01:00 |
|
internal.h
|
fs: Establish locking order for unrelated directories
|
2023-07-27 08:37:26 +02:00 |
|
io_uring.c
|
io_uring: fail NOP if non-zero op flags is passed in
|
2024-06-16 13:28:48 +02:00 |
|
ioctl.c
|
|
|
|
Kconfig
|
|
|
|
Kconfig.binfmt
|
|
|
|
libfs.c
|
libfs: add DEFINE_SIMPLE_ATTRIBUTE_SIGNED for signed value
|
2023-01-18 11:40:55 +01:00 |
|
locks.c
|
filelock: Correct the filelock owner in fcntl_setlk/fcntl_setlk64
|
2024-09-04 13:15:02 +02:00 |
|
Makefile
|
|
|
|
mbcache.c
|
mbcache: Avoid nesting of cache->c_list_lock under bit locks
|
2023-01-18 11:41:59 +01:00 |
|
mount.h
|
|
|
|
mpage.c
|
|
|
|
namei.c
|
fs: move S_ISGID stripping into the vfs_*() helpers
|
2024-02-23 08:24:49 +01:00 |
|
namespace.c
|
mount: handle OOM on mnt_warn_timestamp_expiry
|
2024-11-08 16:20:26 +01:00 |
|
no-block.c
|
|
|
|
nsfs.c
|
|
|
|
open.c
|
ftruncate: pass a signed offset
|
2024-07-05 09:08:31 +02:00 |
|
pipe.c
|
|
|
|
pnode.c
|
pnode: terminate at peers of source
|
2023-01-18 11:41:44 +01:00 |
|
pnode.h
|
|
|
|
posix_acl.c
|
|
|
|
proc_namespace.c
|
|
|
|
read_write.c
|
|
|
|
readdir.c
|
|
|
|
select.c
|
fs/select: rework stack allocation hack for clang
|
2024-03-26 18:22:13 -04:00 |
|
seq_file.c
|
|
|
|
signalfd.c
|
|
|
|
splice.c
|
|
|
|
stack.c
|
|
|
|
stat.c
|
|
|
|
statfs.c
|
statfs: enforce statfs[64] structure initialization
|
2023-05-30 12:44:07 +01:00 |
|
super.c
|
fs: explicitly unregister per-superblock BDIs
|
2024-11-08 16:20:26 +01:00 |
|
sync.c
|
ovl: skip overlayfs superblocks at global sync
|
2023-12-08 08:44:27 +01:00 |
|
timerfd.c
|
|
|
|
userfaultfd.c
|
|
|
|
utimes.c
|
|
|
|
xattr.c
|
fs: don't audit the capability check in simple_xattr_list()
|
2023-01-18 11:40:53 +01:00 |