[PATCH] isofs: Fix out of bound access for corrupted isofs image

From: Jan Kara
Date: Mon Oct 18 2021 - 06:37:41 EST


When isofs image is suitably corrupted isofs_read_inode() can read data
beyond the end of buffer. Sanity-check the directory entry length before
using it.

Signed-off-by: Jan Kara <jack@xxxxxxx>
---
fs/isofs/inode.c | 2 ++
1 file changed, 2 insertions(+)

diff --git a/fs/isofs/inode.c b/fs/isofs/inode.c
index 678e2c51b855..0c6eacfcbeef 100644
--- a/fs/isofs/inode.c
+++ b/fs/isofs/inode.c
@@ -1322,6 +1322,8 @@ static int isofs_read_inode(struct inode *inode, int relocated)

de = (struct iso_directory_record *) (bh->b_data + offset);
de_len = *(unsigned char *) de;
+ if (de_len < sizeof(struct iso_directory_record))
+ goto fail;

if (offset + de_len > bufsize) {
int frag1 = bufsize - offset;
--
2.26.2


--C7zPtVaVf+AK4Oqc--