[PATCH] qnx6: keep the top-level pointer index unsigned in qnx6_block_map()
From: Matthias Goergens
Date: Sun Sep 27 2026 - 18:52:26 EST
qnx6_block_map()'s top-level index is levelptr = no >> bitdelta,
computed from the 32-bit block number no. With bitdelta == 0 (a
depth-0 tree) that is just no, and assigning a value above INT_MAX
to the int levelptr narrows it negative; the levelptr >
QNX6_NO_DIRECT_POINTERS - 1 check then passes and di_block_ptr[levelptr]
is indexed out of bounds (UBSan array-index reports index -16777216
and -8 on crafted images).
Reachable with a crafted inode whose i_size is large enough that mpage
asks for block numbers beyond 2^31.
The only other assignment to levelptr, in the loop, is masked to
ptrbits and so is never negative; making levelptr unsigned leaves that
path unchanged and makes the bounds check reject the large values.
This is independent of bitdelta itself being too large to shift by
(depth * ptrbits >= 32), a separate bug in the same function that a
still-pending patch of mine guards against; that guard leaves the
result of a valid shift assigned to the same int levelptr, so it does
not fix the narrowing this patch does.
Fixes: 5d026c724220 ("fs: initial qnx6fs addition")
Signed-off-by: Matthias Goergens <matthias.goergens@xxxxxxxxx>
---
fs/qnx6/inode.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/qnx6/inode.c b/fs/qnx6/inode.c
index 6de49333acad..7df3eed5142d 100644
--- a/fs/qnx6/inode.c
+++ b/fs/qnx6/inode.c
@@ -117,7 +117,7 @@ static unsigned qnx6_block_map(struct inode *inode, unsigned no)
unsigned block = 0;
struct buffer_head *bh;
__fs32 ptr;
- int levelptr;
+ unsigned int levelptr;
int ptrbits = sbi->s_ptrbits;
int bitdelta;
u32 mask = (1 << ptrbits) - 1;
--
2.55.0