summaryrefslogtreecommitdiff
path: root/scripts/objdiff
diff options
context:
space:
mode:
authorKarl Mehltretter <kmehltretter@gmail.com>2026-08-22 16:33:28 +0200
committerAndrew Morton <akpm@linux-foundation.org>2026-09-13 21:33:28 -0700
commit4fa7aff24ddb76bb896964a02fbdd4bffc085cf6 (patch)
tree0c94fddd6c2f9c4be75b7977737f557c7d980e54 /scripts/objdiff
parent30232f7be8285adbc39218691fe2123d29d10fe9 (diff)
downloadlinux-next-4fa7aff24ddb76bb896964a02fbdd4bffc085cf6.tar.gz
linux-next-4fa7aff24ddb76bb896964a02fbdd4bffc085cf6.zip
squashfs: make the fragment index table bounds check overflow-safe
squashfs_read_fragment_index_table() checks that the table fits before the next one with: if (fragment_table_start + length > next_table) return ERR_PTR(-EINVAL); fragment_table_start comes from the superblock and is not validated before this point. A start of 2^64 - length wraps the sum to zero, so the check passes regardless of next_table and fails to reject the invalid table ordering. length then reaches kmalloc() through squashfs_read_table(). A fragment count of 0xffffffff asks for 64MB, order 14. GFP_KERNEL does not include __GFP_NOWARN, so the page allocator warns before the mount fails with -ENOMEM. With panic_on_warn, the warning panics the kernel. Compare the operands instead of adding them. id.c and export.c avoid the same wrap with an exact-size check. Keep the inequality here because a gap before the next table is still allowed. Link: https://lore.kernel.org/20260822143328.68867-3-kmehltretter@gmail.com Fixes: 1cac63cc9b2f ("Squashfs: add sanity checks to fragment reading at mount time") Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Assisted-by: Claude:claude-opus-5 Cc: Phillip Lougher <phillip@squashfs.org.uk> Cc: <stable@vger.kernel.org>
Diffstat (limited to 'scripts/objdiff')
0 files changed, 0 insertions, 0 deletions