Re: [PATCH v2] ntfs: reject invalid sectors_per_cluster in the boot sector

From: Namjae Jeon

Date: Wed Aug 26 2026 - 07:42:03 EST


On Wed, Aug 26, 2026 at 2:09 PM Dennis Tighe <dennis.tighe@xxxxxxxxx> wrote:
>
> is_boot_sector_ntfs() checks the boot sector's sectors_per_cluster field
> with a range test that rejects 0x81..0xf3 but accepts 0 and other
> non-power-of-two counts. A zero value reaches parse_ntfs_boot_sector():
>
> sectors_per_cluster_bits = ffs(sectors_per_cluster) - 1;
> ...
> vol->cluster_size = vol->sector_size << sectors_per_cluster_bits;
>
> ffs(0) is 0, so sectors_per_cluster_bits becomes (unsigned)-1 and the
> shift is undefined:
>
> UBSAN: shift-out-of-bounds in fs/ntfs/super.c:673:39
> shift exponent 4294967295 is too large for 32-bit type 'int'
>
> This change rejects any non-power-of-two value, since it feeds the
> aforementioned shift via ffs() - 1, which only yields the correct shift for a
> power of two.
>
> Fixes: 6251f0b0de7d ("ntfs: update super block operations")
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: Dennis Tighe <dennis.tighe@xxxxxxxxx>
Applied it to #ntfs-next.
Thanks!