diff options
author | Jan Kara <jack@suse.cz> | 2020-09-25 14:53:08 +0200 |
---|---|---|
committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2020-10-29 10:12:13 +0100 |
commit | 310594d44c3d66c0472054ec4017243c2d4f8339 (patch) | |
tree | c4bf9a56cf7f2c77e0c87ea9c4188052e8f19f2d /fs | |
parent | dcef4a11ad7d7a9c2c907a002415751fa2ed1cd0 (diff) | |
download | linux-stable-310594d44c3d66c0472054ec4017243c2d4f8339.tar.gz linux-stable-310594d44c3d66c0472054ec4017243c2d4f8339.tar.bz2 linux-stable-310594d44c3d66c0472054ec4017243c2d4f8339.zip |
udf: Limit sparing table size
[ Upstream commit 44ac6b829c4e173fdf6df18e6dd86aecf9a3dc99 ]
Although UDF standard allows it, we don't support sparing table larger
than a single block. Check it during mount so that we don't try to
access memory beyond end of buffer.
Reported-by: syzbot+9991561e714f597095da@syzkaller.appspotmail.com
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Diffstat (limited to 'fs')
-rw-r--r-- | fs/udf/super.c | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/fs/udf/super.c b/fs/udf/super.c index 1c42f544096d..a03b8ce5ef0f 100644 --- a/fs/udf/super.c +++ b/fs/udf/super.c @@ -1353,6 +1353,12 @@ static int udf_load_sparable_map(struct super_block *sb, (int)spm->numSparingTables); return -EIO; } + if (le32_to_cpu(spm->sizeSparingTable) > sb->s_blocksize) { + udf_err(sb, "error loading logical volume descriptor: " + "Too big sparing table size (%u)\n", + le32_to_cpu(spm->sizeSparingTable)); + return -EIO; + } for (i = 0; i < spm->numSparingTables; i++) { loc = le32_to_cpu(spm->locSparingTable[i]); |