[PATCH] fs/ntfs3: validate filename replay destination size

From: sungbyeongchan

Date: Sun Oct 04 2026 - 08:36:37 EST


UpdateFileNameAllocation accepts a terminal index entry because the
generic validator only requires the 16-byte NTFS_DE header. The action then
writes the 56-byte duplicate-info field after that header without
checking either the entry size or the remaining allocation.

Require the complete destination to fit both the selected entry and the
allocated replay buffer before copying it.

Fixes: b46acd6a6a62 ("fs/ntfs3: Add NTFS journal")
Signed-off-by: sungbyeongchan <tjdqudcks0424@xxxxxxxxx>
---
fs/ntfs3/fslog.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/fs/ntfs3/fslog.c b/fs/ntfs3/fslog.c
index ed50c1d0c23e..f95fa39e1f00 100644
--- a/fs/ntfs3/fslog.c
+++ b/fs/ntfs3/fslog.c
@@ -3731,7 +3731,13 @@ static int do_action(struct ntfs_log *log, struct OPEN_ATTR_ENRTY *oe,
if (!check_lsn(&ib->rhdr, rlsn))
goto out;
if (!check_index_buffer(ib, bytes) ||
- !check_if_alloc_index(hdr, aoff)) {
+ !check_if_alloc_index(hdr, aoff) || roff > bytes ||
+ aoff > bytes - roff ||
+ sizeof(*e) + offsetof(struct ATTR_FILE_NAME, dup) +
+ sizeof(fname->dup) > bytes - roff - aoff ||
+ le16_to_cpu(e->size) <
+ sizeof(*e) + offsetof(struct ATTR_FILE_NAME, dup) +
+ sizeof(fname->dup)) {
goto dirty_vol;
}

--
2.43.0