summaryrefslogtreecommitdiffstats
path: root/drivers/block/nbd.c
diff options
context:
space:
mode:
authorJens Axboe <axboe@kernel.dk>2018-09-04 11:52:34 -0600
committerJens Axboe <axboe@kernel.dk>2018-09-04 11:54:58 -0600
commitbc811f05d77f47059c197a98b6ad242eb03999cb (patch)
treee96cabff009625665432d1b98fba898eabaa89ba /drivers/block/nbd.c
parent3111885015b458c97b4cf272e2a87f1d6f0ed06a (diff)
downloadlinux-stable-bc811f05d77f47059c197a98b6ad242eb03999cb.tar.gz
linux-stable-bc811f05d77f47059c197a98b6ad242eb03999cb.tar.bz2
linux-stable-bc811f05d77f47059c197a98b6ad242eb03999cb.zip
nbd: don't allow invalid blocksize settings
syzbot reports a divide-by-zero off the NBD_SET_BLKSIZE ioctl. We need proper validation of the input here. Not just if it's zero, but also if the value is a power-of-2 and in a valid range. Add that. Cc: stable@vger.kernel.org Reported-by: syzbot <syzbot+25dbecbec1e62c6b0dd4@syzkaller.appspotmail.com> Reviewed-by: Josef Bacik <josef@toxicpanda.com> Signed-off-by: Jens Axboe <axboe@kernel.dk>
Diffstat (limited to 'drivers/block/nbd.c')
-rw-r--r--drivers/block/nbd.c3
1 files changed, 3 insertions, 0 deletions
diff --git a/drivers/block/nbd.c b/drivers/block/nbd.c
index 3863c00372bb..14a51254c3db 100644
--- a/drivers/block/nbd.c
+++ b/drivers/block/nbd.c
@@ -1239,6 +1239,9 @@ static int __nbd_ioctl(struct block_device *bdev, struct nbd_device *nbd,
case NBD_SET_SOCK:
return nbd_add_socket(nbd, arg, false);
case NBD_SET_BLKSIZE:
+ if (!arg || !is_power_of_2(arg) || arg < 512 ||
+ arg > PAGE_SIZE)
+ return -EINVAL;
nbd_size_set(nbd, arg,
div_s64(config->bytesize, arg));
return 0;