| From 46901760b46064964b41015d00c140c83aa05bcf Mon Sep 17 00:00:00 2001 |
| From: Insu Yun <wuninsu@gmail.com> |
| Date: Fri, 12 Feb 2016 01:15:59 -0500 |
| Subject: ext4: fix potential integer overflow |
| |
| From: Insu Yun <wuninsu@gmail.com> |
| |
| commit 46901760b46064964b41015d00c140c83aa05bcf upstream. |
| |
| Since sizeof(ext_new_group_data) > sizeof(ext_new_flex_group_data), |
| integer overflow could be happened. |
| Therefore, need to fix integer overflow sanitization. |
| |
| Signed-off-by: Insu Yun <wuninsu@gmail.com> |
| Signed-off-by: Theodore Ts'o <tytso@mit.edu> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| |
| --- |
| fs/ext4/resize.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| --- a/fs/ext4/resize.c |
| +++ b/fs/ext4/resize.c |
| @@ -198,7 +198,7 @@ static struct ext4_new_flex_group_data * |
| if (flex_gd == NULL) |
| goto out3; |
| |
| - if (flexbg_size >= UINT_MAX / sizeof(struct ext4_new_flex_group_data)) |
| + if (flexbg_size >= UINT_MAX / sizeof(struct ext4_new_group_data)) |
| goto out2; |
| flex_gd->count = flexbg_size; |
| |