[PATCH v3 6/6] qnx6: validate sb_blocksize before dividing in qnx6_mmi_fill_super()
From: Hui Peng
Date: Thu Sep 24 2026 - 03:48:14 EST
In qnx6_mmi_fill_super(), sb_blocksize is read from MMI superblock header
without verifying if it is zero or non-power-of-two. A corrupted MMI
image with sb_blocksize == 0 causes a divide-by-zero exception (#DE) in
qnx6_mmi_fill_super().
Validate sb_blocksize via sb_set_blocksize() and verify it is non-zero
before performing division.
Fixes: 5d026c724220 ("fs: initial qnx6fs addition")
Cc: stable@xxxxxxxxxxxxxxx
Tested-by: Matthias Goergens <matthias.goergens@xxxxxxxxx>
Reviewed-by: Matthias Goergens <matthias.goergens@xxxxxxxxx>
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@xxxxxxxxx>
---
Changes in v3:
- Add Tested-by and Reviewed-by tags from Matthias Goergens.
- Update Fixes: tag SHA to 5d026c724220 ("fs: initial qnx6fs addition").
Changes in v2:
- Split out as patch 6/6 as requested by maintainers.
fs/qnx6/inode.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/fs/qnx6/inode.c b/fs/qnx6/inode.c
index a32066d98188..b8f9e6022e11 100644
--- a/fs/qnx6/inode.c
+++ b/fs/qnx6/inode.c
@@ -375,6 +375,11 @@ static int qnx6_mmi_fill_super(struct super_block *s, int silent)
goto out;
}
+ if (!sb_set_blocksize(s, fs32_to_cpu(sbi, mmi_fs->sb_blocksize))) {
+ pr_err("bad blocksize\n");
+ goto out;
+ }
+
return 0;
out:
--
2.55.0.1082.g2b9226bbc0-goog