Re: [PATCH] ufs: validate block and fragment shifts

From: Matheus Alves de Almeida

Date: Wed Oct 07 2026 - 23:30:39 EST


Em 2026-09-25 01:33, Matheus Alves de Almeida escreveu:
Currently, ufs_fill_super() accepts images with an fs_bshift and an
fs_fshift that do not match their respective size fields. This causes
UBSAN shift-out-of-bounds issues in the bad fs_bshift case and an
out-of-bounds read and kernel oops in the bad fs_fshift case.

Make the ufs_fill_super() function check that these fields agree with
their size counterparts.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: syzbot+5585f47221c0de04168d@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=5585f47221c0de04168d
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Matheus Alves de Almeida <matheus.aalmeida@xxxxxxxxxxxx>

Hi,

Gentle ping on this. Has anyone been able to take a look at it yet?

Matheus