summaryrefslogtreecommitdiffstats
path: root/fs
diff options
context:
space:
mode:
authorYue Hu <huyue2@coolpad.com>2022-10-21 16:53:25 +0800
committerGao Xiang <hsiangkao@linux.alibaba.com>2022-11-08 14:44:13 +0800
commite5126de138caef0eedb3d6431059c0c5581a1a5d (patch)
treee0b57c7ab5e71c75bc2b47984829c948a6baded2 /fs
parentf0c4d9fc9cc9462659728d168387191387e903cc (diff)
downloadlinux-stable-e5126de138caef0eedb3d6431059c0c5581a1a5d.tar.gz
linux-stable-e5126de138caef0eedb3d6431059c0c5581a1a5d.tar.bz2
linux-stable-e5126de138caef0eedb3d6431059c0c5581a1a5d.zip
erofs: fix general protection fault when reading fragment
As syzbot reported [1], the fragment feature sb flag is not set, so packed_inode != NULL needs to be checked in z_erofs_read_fragment(). [1] https://lore.kernel.org/all/0000000000002e7a8905eb841ddd@google.com/ Reported-by: syzbot+3faecbfd845a895c04cb@syzkaller.appspotmail.com Fixes: b15b2e307c3a ("erofs: support on-disk compressed fragments data") Signed-off-by: Yue Hu <huyue2@coolpad.com> Reviewed-by: Gao Xiang <hsiangkao@linux.alibaba.com> Reviewed-by: Chao Yu <chao@kernel.org> Link: https://lore.kernel.org/r/20221021085325.25788-1-zbestahu@gmail.com Signed-off-by: Gao Xiang <hsiangkao@linux.alibaba.com>
Diffstat (limited to 'fs')
-rw-r--r--fs/erofs/zdata.c3
1 files changed, 3 insertions, 0 deletions
diff --git a/fs/erofs/zdata.c b/fs/erofs/zdata.c
index c7f24fc7efd5..d6caf275be77 100644
--- a/fs/erofs/zdata.c
+++ b/fs/erofs/zdata.c
@@ -660,6 +660,9 @@ static int z_erofs_read_fragment(struct inode *inode, erofs_off_t pos,
u8 *src, *dst;
unsigned int i, cnt;
+ if (!packed_inode)
+ return -EFSCORRUPTED;
+
pos += EROFS_I(inode)->z_fragmentoff;
for (i = 0; i < len; i += cnt) {
cnt = min_t(unsigned int, len - i,