Re: [PATCH] ocfs2: validate rl_used against rl_count in refcount block validator

From: Andrew Morton

Date: Fri Jul 10 2026 - 16:37:24 EST


On Thu, 9 Jul 2026 15:26:09 +0200 Ibrahim Hashimov <security@xxxxxxxxxxxx> wrote:

> ocfs2_find_refcount_rec_in_rl() walks the on-disk refcount record
> array with:
>
> for (; i < le16_to_cpu(rb->rf_records.rl_used); i++) {
> rec = &rb->rf_records.rl_recs[i];
> ...
>
> rl_recs[] lives in a single metadata block (4096 bytes on the common
> configuration), so its real capacity is fixed by
> ocfs2_refcount_recs_per_rb(sb) (247 records for a 4K block with the
> 16-byte ocfs2_refcount_rec). rl_used and rl_count are both read
> directly off disk by ocfs2_validate_refcount_block() and are never
> checked against that capacity, nor against each other, before any
> refcount/reflink/CoW operation walks the array.
>
> A crafted (or corrupted) refcount block with rl_used == 0xffff makes
> the loop above walk far past the end of the block, dereferencing
> rl_recs[i] for i up to 65534. The resulting index is then handed to
> the sibling ocfs2_insert_refcount_rec(), whose insert-shift does:
>
> ...
>
> Add the equivalent pair of checks to ocfs2_validate_refcount_block():
>

Thanks. AI review might have found another bug in there:
https://sashiko.dev/#/patchset/20260709132609.44233-1-security@xxxxxxxxxxxx