[PATCH] sysfs: prevent writing excessively large files
From: Edward Adam Davis
Date: Tue Sep 15 2026 - 08:42:20 EST
Since atomic_write_len is not configured for sysfs_file_kfops_rw, a large
file write via sysfs_kf_write() may result in an out-of-bounds read when
checking for the null terminator of a string element in the kobject_actions
array within kobject_action_type(), potentially hitting:
BUG: KASAN: global-out-of-bounds in kobject_action_type lib/kobject_uevent.c:86 [inline]
BUG: KASAN: global-out-of-bounds in kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
Read of size 1 at addr ffffffff8d72559f by task syz.0.17/5917
Call Trace:
kobject_action_type lib/kobject_uevent.c:86 [inline]
kobject_synth_uevent+0x79d/0x7d0 lib/kobject_uevent.c:200
bus_uevent_store+0x3d/0x90 drivers/base/bus.c:917
bus_attr_store+0x74/0xb0 drivers/base/bus.c:172
sysfs_kf_write+0xf2/0x150 fs/sysfs/file.c:145
kernfs_fop_write_iter+0x3e0/0x5f0 fs/kernfs/file.c:345
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x6af/0x1050 fs/read_write.c:687
Add atomic_write_len for sysfs_file_kfops_rw and sysfs_file_kfops_wo
properly.
Fixes: f6acf8bb6a40 ("sysfs, kernfs: introduce kernfs_ops")
Reported-by: syzbot+9a321aea9d851b299486@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=9a321aea9d851b299486
Tested-by: syzbot+9a321aea9d851b299486@xxxxxxxxxxxxxxxxxxxxxxxxx
Signed-off-by: Edward Adam Davis <eadavis@xxxxxxxx>
---
fs/sysfs/file.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/fs/sysfs/file.c b/fs/sysfs/file.c
index cd5bb0f9fee6..a63130d18680 100644
--- a/fs/sysfs/file.c
+++ b/fs/sysfs/file.c
@@ -228,10 +228,12 @@ static const struct kernfs_ops sysfs_file_kfops_ro = {
};
static const struct kernfs_ops sysfs_file_kfops_wo = {
+ .atomic_write_len = PAGE_SIZE,
.write = sysfs_kf_write,
};
static const struct kernfs_ops sysfs_file_kfops_rw = {
+ .atomic_write_len = PAGE_SIZE,
.seq_show = sysfs_kf_seq_show,
.write = sysfs_kf_write,
};
--
2.43.0