| From 722cf9d454e6142a2f3ea756b644e5805d88431f Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Fri, 11 Jul 2025 19:01:20 +0200 |
| Subject: udf: Verify partition map count |
| |
| From: Jan Kara <jack@suse.cz> |
| |
| [ Upstream commit 1a11201668e8635602577dcf06f2e96c591d8819 ] |
| |
| Verify that number of partition maps isn't insanely high which can lead |
| to large allocation in udf_sb_alloc_partition_maps(). All partition maps |
| have to fit in the LVD which is in a single block. |
| |
| Reported-by: syzbot+478f2c1a6f0f447a46bb@syzkaller.appspotmail.com |
| Signed-off-by: Jan Kara <jack@suse.cz> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| fs/udf/super.c | 13 +++++++++++-- |
| 1 file changed, 11 insertions(+), 2 deletions(-) |
| |
| diff --git a/fs/udf/super.c b/fs/udf/super.c |
| index 1c8a736b3309..b2f168b0a0d1 100644 |
| --- a/fs/udf/super.c |
| +++ b/fs/udf/super.c |
| @@ -1440,7 +1440,7 @@ static int udf_load_logicalvol(struct super_block *sb, sector_t block, |
| struct genericPartitionMap *gpm; |
| uint16_t ident; |
| struct buffer_head *bh; |
| - unsigned int table_len; |
| + unsigned int table_len, part_map_count; |
| int ret; |
| |
| bh = udf_read_tagged(sb, block, block, &ident); |
| @@ -1461,7 +1461,16 @@ static int udf_load_logicalvol(struct super_block *sb, sector_t block, |
| "logical volume"); |
| if (ret) |
| goto out_bh; |
| - ret = udf_sb_alloc_partition_maps(sb, le32_to_cpu(lvd->numPartitionMaps)); |
| + |
| + part_map_count = le32_to_cpu(lvd->numPartitionMaps); |
| + if (part_map_count > table_len / sizeof(struct genericPartitionMap1)) { |
| + udf_err(sb, "error loading logical volume descriptor: " |
| + "Too many partition maps (%u > %u)\n", part_map_count, |
| + table_len / (unsigned)sizeof(struct genericPartitionMap1)); |
| + ret = -EIO; |
| + goto out_bh; |
| + } |
| + ret = udf_sb_alloc_partition_maps(sb, part_map_count); |
| if (ret) |
| goto out_bh; |
| |
| -- |
| 2.39.5 |
| |