[PATCH] udf: fix return value for non-recorded-allocated extents in udf_map_block()

From: Giorgi Kobakhia

Date: Mon Sep 28 2026 - 16:05:10 EST


In the if (!(map->iflags & UDF_MAP_CREATE)) check the ret is set to
inode_bmap(inode, map->lblk, &epos, &eloc, &elen, &offset, &etype),
which returns 1 on success, -errno on error and 0 on EOF. ret is set
back to 0 only if the etype of the extent is EXT_RECORDED_ALLOCATED.
In other cases the ret is still equal to 1, which is not a valid return
value for udf_map_block() and is later accessed in page_get_link().

Oops: general protection fault
KASAN: maybe wild-memory-access
RIP: 0010:page_get_link (fs/namei.c:6503)
Call Trace:
vfs_readlink (fs/namei.c:6419)
do_readlinkat (fs/stat.c:583)
__x64_sys_readlink (fs/stat.c:605 fs/stat.c:602 fs/stat.c:602)

Move the reset to 0 line outside the if, so udf_map_block() returns either
0 or -errno, even if the extent type is not EXT_RECORDED_ALLOCATED.

Fixes: c226964ec786 ("udf: refactor inode_bmap() to handle error")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Tested-by: Xiang Mei <xmei5@xxxxxxx>
Signed-off-by: Giorgi Kobakhia <gkobakhi@xxxxxxx>
---
fs/udf/inode.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/udf/inode.c b/fs/udf/inode.c
index e45e546a739a..2f04c4f0e1b8 100644
--- a/fs/udf/inode.c
+++ b/fs/udf/inode.c
@@ -372,8 +372,8 @@ static int udf_map_block(struct inode *inode, struct udf_map_rq *map)
map->pblk = udf_get_lb_pblock(inode->i_sb, &eloc,
offset);
map->oflags |= UDF_BLK_MAPPED;
- ret = 0;
}
+ ret = 0;
out_read:
up_read(&iinfo->i_data_sem);
brelse(epos.bh);
--
2.43.0