summaryrefslogtreecommitdiffstats
path: root/fs/udf/super.c
diff options
context:
space:
mode:
authorJan Kara <jack@suse.cz>2020-09-25 14:53:08 +0200
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2020-10-29 09:05:44 +0100
commitf96c6586a812a006876cbed6ba2fbd68f77f0389 (patch)
tree890d60c2a55330c0485f7f20121561e60d011654 /fs/udf/super.c
parent4a47581cf010dc351d8069978080fdb000c0776d (diff)
downloadlinux-stable-f96c6586a812a006876cbed6ba2fbd68f77f0389.tar.gz
linux-stable-f96c6586a812a006876cbed6ba2fbd68f77f0389.tar.bz2
linux-stable-f96c6586a812a006876cbed6ba2fbd68f77f0389.zip
udf: Limit sparing table size
[ Upstream commit 44ac6b829c4e173fdf6df18e6dd86aecf9a3dc99 ] Although UDF standard allows it, we don't support sparing table larger than a single block. Check it during mount so that we don't try to access memory beyond end of buffer. Reported-by: syzbot+9991561e714f597095da@syzkaller.appspotmail.com Signed-off-by: Jan Kara <jack@suse.cz> Signed-off-by: Sasha Levin <sashal@kernel.org>
Diffstat (limited to 'fs/udf/super.c')
-rw-r--r--fs/udf/super.c6
1 files changed, 6 insertions, 0 deletions
diff --git a/fs/udf/super.c b/fs/udf/super.c
index 4abdba453885..c8c037e8e57b 100644
--- a/fs/udf/super.c
+++ b/fs/udf/super.c
@@ -1391,6 +1391,12 @@ static int udf_load_sparable_map(struct super_block *sb,
(int)spm->numSparingTables);
return -EIO;
}
+ if (le32_to_cpu(spm->sizeSparingTable) > sb->s_blocksize) {
+ udf_err(sb, "error loading logical volume descriptor: "
+ "Too big sparing table size (%u)\n",
+ le32_to_cpu(spm->sizeSparingTable));
+ return -EIO;
+ }
for (i = 0; i < spm->numSparingTables; i++) {
loc = le32_to_cpu(spm->locSparingTable[i]);