Re: [PATCH] ufs: validate block and fragment shifts
From: Matheus Alves de Almeida
Date: Wed Oct 07 2026 - 23:30:39 EST
Em 2026-09-25 01:33, Matheus Alves de Almeida escreveu:
Currently, ufs_fill_super() accepts images with an fs_bshift and an
fs_fshift that do not match their respective size fields. This causes
UBSAN shift-out-of-bounds issues in the bad fs_bshift case and an
out-of-bounds read and kernel oops in the bad fs_fshift case.
Make the ufs_fill_super() function check that these fields agree with
their size counterparts.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: syzbot+5585f47221c0de04168d@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=5585f47221c0de04168d
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Matheus Alves de Almeida <matheus.aalmeida@xxxxxxxxxxxx>
Hi,
Gentle ping on this. Has anyone been able to take a look at it yet?
Matheus