[PATCH ntfs] fs/ntfs3: fix out-of-bounds write in UpdateFileName replay

From: Xue Boyang

Date: Tue Sep 29 2026 - 05:05:18 EST


During $LogFile replay, do_action()'s UpdateFileNameRoot and
UpdateFileNameAllocation cases write sizeof(NTFS_DUP_INFO) = 0x38 bytes
into the ATTR_FILE_NAME structure that follows the target index entry:

e = Add2Ptr(attr, le16_to_cpu(lrh->attr_off));
fname = (struct ATTR_FILE_NAME *)(e + 1);
memmove(&fname->dup, data, sizeof(fname->dup));

The gates that run before the write (check_if_index_root and
check_if_root_index) only validate that the record and entry offsets
land on boundaries. Neither checks that the entry's key_size is large
enough to hold a struct ATTR_FILE_NAME, whose minimum size is
SIZEOF_ATTRIBUTE_FILENAME (0x44). de_get_fname() applies exactly this
check at every other call site; the replay path omits it.

With a crafted $LogFile whose UpdateFileNameRoot record points at a
16-byte entry with key_size = 0 placed at the end of a crafted $I30
INDEX_ROOT, the write lands past the end of the kmalloc(record_size)
MFT record allocation:

BUG: KASAN: slab-out-of-bounds in do_action+0x14af/0x1d35
Write of size 56 at addr ffff888004046be8 by task mount/71
...
__asan_memmove+0x3c/0x60
do_action+0x14af/0x1d35
log_replay (fs/ntfs3/fslog.c)
ntfs_loadlog_and_replay+0x2cb/0x300
ntfs_fill_super+0x1375/0x22d0
...

The write content is fully attacker-controlled (redo data from the log
record) and the trigger is deterministic on every rw mount, no race.

Reject the operation when key_size is below SIZEOF_ATTRIBUTE_FILENAME
in both cases, matching de_get_fname().

Fixes: b46acd6a6a62 ("fs/ntfs3: Add NTFS3 filesystem")
Assisted-by: GLM:zhipu-coding-plan/glm-5.3
Signed-off-by: Xue Boyang <fuchen.dust@xxxxxxxxx>
---
fs/ntfs3/fslog.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/fs/ntfs3/fslog.c b/fs/ntfs3/fslog.c
index 498f63da2b96..ba61767cab3f 100644
--- a/fs/ntfs3/fslog.c
+++ b/fs/ntfs3/fslog.c
@@ -3557,8 +3557,10 @@ static int do_action(struct ntfs_log *log, struct OPEN_ATTR_ENRTY *oe,
}

e = Add2Ptr(attr, le16_to_cpu(lrh->attr_off));
+ if (le16_to_cpu(e->key_size) < SIZEOF_ATTRIBUTE_FILENAME)
+ goto dirty_vol;
fname = (struct ATTR_FILE_NAME *)(e + 1);
- memmove(&fname->dup, data, sizeof(fname->dup)); //
+ memmove(&fname->dup, data, sizeof(fname->dup));
mi->dirty = true;
break;

@@ -3742,6 +3744,8 @@ static int do_action(struct ntfs_log *log, struct OPEN_ATTR_ENRTY *oe,
goto dirty_vol;
}

+ if (le16_to_cpu(e->key_size) < SIZEOF_ATTRIBUTE_FILENAME)
+ goto dirty_vol;
fname = (struct ATTR_FILE_NAME *)(e + 1);
memmove(&fname->dup, data, sizeof(fname->dup));

--
2.53.0