[PATCH v2] 9p: bound the xattr size used to allocate the ACL buffer

From: Nguyen Ngoc Thang

Date: Sat Sep 19 2026 - 09:29:47 EST


v9fs_fid_get_acl() sizes its kzalloc() buffer from the xattr length
reported by the 9p server. A server, or a syzbot-style fake one, can
report an arbitrarily large value. When it exceeds what the page
allocator can serve, mounting with posixacl,access=client trips:

WARNING: mm/page_alloc.c:5340 at __alloc_frozen_pages_noprof
___kmalloc_large_node
v9fs_fid_get_acl
v9fs_get_acl
v9fs_inode_from_fid_dotl
v9fs_get_tree

The allocation cannot succeed anyway and the failure is already mapped
to -EIO by __v9fs_get_acl(), so reject sizes above KMALLOC_MAX_SIZE
up front instead of tripping the allocator's warning. Larger ACLs that
kmalloc can still serve are unaffected.

Reported-by: syzbot+de6fd6789748a8aa64a0@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=de6fd6789748a8aa64a0
Fixes: 85ff872d3f4a ("fs/9p: Implement POSIX ACL permission checking function")
Signed-off-by: Nguyen Ngoc Thang <ngocthang2710.1999@xxxxxxxxx>
---
Hi Christian,

Thanks, agreed: XATTR_SIZE_MAX would wrongly limit servers with larger
9p xattrs. v2 caps at KMALLOC_MAX_SIZE, which is already the effective
limit, so nothing that worked before changes; it only avoids the
allocator warning for sizes that could never be served.

v2:
- Bound by KMALLOC_MAX_SIZE instead of XATTR_SIZE_MAX so that ACLs from
servers with larger 9p xattrs keep working (Christian).
- Reworded the commit message accordingly.

v1: https://lore.kernel.org/all/20260919102958.142460-1-ngocthang2710.1999@xxxxxxxxx/

fs/9p/acl.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/fs/9p/acl.c b/fs/9p/acl.c
index 0dd7e72bbdd3..915877cbaded 100644
--- a/fs/9p/acl.c
+++ b/fs/9p/acl.c
@@ -29,8 +29,8 @@ static struct posix_acl *v9fs_fid_get_acl(struct p9_fid *fid, const char *name)
return ERR_PTR(size);
if (size == 0)
return ERR_PTR(-ENODATA);
- /* the size is server-controlled; a valid ACL fits in an xattr */
- if (size > XATTR_SIZE_MAX)
+ /* the size is server-controlled; it cannot exceed what kmalloc serves */
+ if (size > KMALLOC_MAX_SIZE)
return ERR_PTR(-E2BIG);

value = kzalloc(size, GFP_NOFS);
--
2.43.0