mirror of
https://gitee.com/bianbu-linux/linux-6.6
synced 2025-04-24 14:07:52 -04:00
udf: Avoid excessive partition lengths
[ Upstream commit ebbe26fd54a9621994bc16b14f2ba8f84c089693 ] Avoid mounting filesystems where the partition would overflow the 32-bits used for block number. Also refuse to mount filesystems where the partition length is so large we cannot safely index bits in a block bitmap. Link: https://patch.msgid.link/20240620130403.14731-1-jack@suse.cz Signed-off-by: Jan Kara <jack@suse.cz> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
parent
415f3634d5
commit
a563307619
1 changed files with 15 additions and 0 deletions
|
@ -1080,12 +1080,19 @@ static int udf_fill_partdesc_info(struct super_block *sb,
|
||||||
struct udf_part_map *map;
|
struct udf_part_map *map;
|
||||||
struct udf_sb_info *sbi = UDF_SB(sb);
|
struct udf_sb_info *sbi = UDF_SB(sb);
|
||||||
struct partitionHeaderDesc *phd;
|
struct partitionHeaderDesc *phd;
|
||||||
|
u32 sum;
|
||||||
int err;
|
int err;
|
||||||
|
|
||||||
map = &sbi->s_partmaps[p_index];
|
map = &sbi->s_partmaps[p_index];
|
||||||
|
|
||||||
map->s_partition_len = le32_to_cpu(p->partitionLength); /* blocks */
|
map->s_partition_len = le32_to_cpu(p->partitionLength); /* blocks */
|
||||||
map->s_partition_root = le32_to_cpu(p->partitionStartingLocation);
|
map->s_partition_root = le32_to_cpu(p->partitionStartingLocation);
|
||||||
|
if (check_add_overflow(map->s_partition_root, map->s_partition_len,
|
||||||
|
&sum)) {
|
||||||
|
udf_err(sb, "Partition %d has invalid location %u + %u\n",
|
||||||
|
p_index, map->s_partition_root, map->s_partition_len);
|
||||||
|
return -EFSCORRUPTED;
|
||||||
|
}
|
||||||
|
|
||||||
if (p->accessType == cpu_to_le32(PD_ACCESS_TYPE_READ_ONLY))
|
if (p->accessType == cpu_to_le32(PD_ACCESS_TYPE_READ_ONLY))
|
||||||
map->s_partition_flags |= UDF_PART_FLAG_READ_ONLY;
|
map->s_partition_flags |= UDF_PART_FLAG_READ_ONLY;
|
||||||
|
@ -1141,6 +1148,14 @@ static int udf_fill_partdesc_info(struct super_block *sb,
|
||||||
bitmap->s_extPosition = le32_to_cpu(
|
bitmap->s_extPosition = le32_to_cpu(
|
||||||
phd->unallocSpaceBitmap.extPosition);
|
phd->unallocSpaceBitmap.extPosition);
|
||||||
map->s_partition_flags |= UDF_PART_FLAG_UNALLOC_BITMAP;
|
map->s_partition_flags |= UDF_PART_FLAG_UNALLOC_BITMAP;
|
||||||
|
/* Check whether math over bitmap won't overflow. */
|
||||||
|
if (check_add_overflow(map->s_partition_len,
|
||||||
|
sizeof(struct spaceBitmapDesc) << 3,
|
||||||
|
&sum)) {
|
||||||
|
udf_err(sb, "Partition %d is too long (%u)\n", p_index,
|
||||||
|
map->s_partition_len);
|
||||||
|
return -EFSCORRUPTED;
|
||||||
|
}
|
||||||
udf_debug("unallocSpaceBitmap (part %d) @ %u\n",
|
udf_debug("unallocSpaceBitmap (part %d) @ %u\n",
|
||||||
p_index, bitmap->s_extPosition);
|
p_index, bitmap->s_extPosition);
|
||||||
}
|
}
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue