Re: [PATCH] xfs: validate attr entry pointer before field access

From: Darrick J. Wong

Date: Tue Jul 28 2026 - 11:32:50 EST


On Tue, Jul 28, 2026 at 03:43:40PM +0800, Hongling Zeng wrote:
> xfs_attr3_leaf_verify_entry() accesses lentry/rentry fields (namelen,
> valuelen) before checking if the entry pointer itself is within bounds.
> If nameidx is crafted to point near the end of the buffer, these field
> accesses can read out-of-bounds before the bounds check at
> name_end > buf_end is performed.
>
> Add explicit bounds checks for entry pointers before accessing their
> fields. Use offsetof() to check that the start of the flexible array
> member (nameval/name) is within bounds, which ensures all preceding
> fields are safe to access.
>
> Fixes: c84760659dcf2 ("xfs: check attribute leaf block structure")
> Cc: <stable@xxxxxxxxxxxxxxx>

Cc: <stable@xxxxxxxxxxxxxxx> # v5.5

(for automatic backport)

> Signed-off-by: Hongling Zeng <zenghongling@xxxxxxxxxx>

Looks correct to me;
Reviewed-by: "Darrick J. Wong" <djwong@xxxxxxxxxx>

--D

> ---
> fs/xfs/libxfs/xfs_attr_leaf.c | 14 ++++++++++++++
> 1 file changed, 14 insertions(+)
>
> diff --git a/fs/xfs/libxfs/xfs_attr_leaf.c b/fs/xfs/libxfs/xfs_attr_leaf.c
> index 86c5c09a5db4..b6288395f853 100644
> --- a/fs/xfs/libxfs/xfs_attr_leaf.c
> +++ b/fs/xfs/libxfs/xfs_attr_leaf.c
> @@ -325,6 +325,13 @@ xfs_attr3_leaf_verify_entry(
> */
> if (ent->flags & XFS_ATTR_LOCAL) {
> lentry = xfs_attr3_leaf_name_local(leaf, idx);
> +
> + /* Validate lentry pointer is within bounds before field access */
> + if ((char *)lentry >= buf_end)
> + return __this_address;
> + if ((char *)lentry + offsetof(struct xfs_attr_leaf_name_local, nameval) > buf_end)
> + return __this_address;
> +
> namesize = xfs_attr_leaf_entsize_local(lentry->namelen,
> be16_to_cpu(lentry->valuelen));
> name_end = (char *)lentry + namesize;
> @@ -332,6 +339,13 @@ xfs_attr3_leaf_verify_entry(
> return __this_address;
> } else {
> rentry = xfs_attr3_leaf_name_remote(leaf, idx);
> +
> + /* Validate rentry pointer is within bounds before field access */
> + if ((char *)rentry >= buf_end)
> + return __this_address;
> + if ((char *)rentry + offsetof(struct xfs_attr_leaf_name_remote, name) > buf_end)
> + return __this_address;
> +
> namesize = xfs_attr_leaf_entsize_remote(rentry->namelen);
> name_end = (char *)rentry + namesize;
> if (rentry->namelen == 0)
> --
> 2.25.1
>
>