[PATCH] fs/ntfs3: reject overflowing replay bitmap ranges
From: sungbyeongchan
Date: Sun Oct 04 2026 - 08:37:09 EST
The BITMAP_RANGE bounds checks perform off + 7 and off + bits + 7 in
u32. Crafted journal values can wrap both checks and make the bitmap
helper perform a word-sized read-modify-write outside the replay buffer.
Check every addition before byte rounding for both set and clear actions.
Fixes: b46acd6a6a62 ("fs/ntfs3: Add NTFS journal")
Signed-off-by: sungbyeongchan <tjdqudcks0424@xxxxxxxxx>
---
fs/ntfs3/fslog.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/fs/ntfs3/fslog.c b/fs/ntfs3/fslog.c
index ed50c1d0c23e..38873c02d30d 100644
--- a/fs/ntfs3/fslog.c
+++ b/fs/ntfs3/fslog.c
@@ -3746,8 +3746,10 @@ static int do_action(struct ntfs_log *log, struct OPEN_ATTR_ENRTY *oe,
off = le32_to_cpu(((struct BITMAP_RANGE *)data)->bitmap_off);
bits = le32_to_cpu(((struct BITMAP_RANGE *)data)->bits);
- if (cbo + (off + 7) / 8 > lco ||
- cbo + ((off + bits + 7) / 8) > lco) {
+ if (check_add_overflow(off, 7u, &nsize) ||
+ check_add_overflow(off, bits, &t32) ||
+ check_add_overflow(t32, 7u, &t32) ||
+ cbo + nsize / 8 > lco || cbo + t32 / 8 > lco) {
goto dirty_vol;
}
@@ -3759,8 +3761,10 @@ static int do_action(struct ntfs_log *log, struct OPEN_ATTR_ENRTY *oe,
off = le32_to_cpu(((struct BITMAP_RANGE *)data)->bitmap_off);
bits = le32_to_cpu(((struct BITMAP_RANGE *)data)->bits);
- if (cbo + (off + 7) / 8 > lco ||
- cbo + ((off + bits + 7) / 8) > lco) {
+ if (check_add_overflow(off, 7u, &nsize) ||
+ check_add_overflow(off, bits, &t32) ||
+ check_add_overflow(t32, 7u, &t32) ||
+ cbo + nsize / 8 > lco || cbo + t32 / 8 > lco) {
goto dirty_vol;
}
--
2.43.0