[PATCH v4 6/6] qnx6: validate sb_blocksize before dividing in qnx6_mmi_fill_super()
From: Hui Peng
Date: Tue Sep 29 2026 - 23:17:04 EST
In qnx6_mmi_fill_super(), sb1->sb_blocksize is read from disk and used as a
divisor in QNX6_SUPERBLOCK_AREA / fs32_to_cpu(sbi, sb1->sb_blocksize). If
sb1->sb_blocksize is 0, it causes a division by zero in kernel space.
Validate sb1->sb_blocksize is non-zero before performing the division and
abort mount if it is zero.
Tested in QEMU against tip of mainline commit 62f4c998b297 ("Merge tag 'parisc-for-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/parisc-linux")
using a loop-device reproducer mounting an image with sb_blocksize = 0:
verified that mount is rejected cleanly with -EINVAL (rc=-1 errno=22)
before division occurs.
Fixes: 5d026c724220 ("fs: initial qnx6fs addition")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@xxxxxxxxx>
---
Changes in v4:
- Rebased cleanly onto upstream mainline commit 62f4c998b297.
- Added QEMU test procedure and verification details in commit message body.
fs/qnx6/super_mmi.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/fs/qnx6/super_mmi.c b/fs/qnx6/super_mmi.c
index 5f62df30467b..5d41f028bf80 100644
--- a/fs/qnx6/super_mmi.c
+++ b/fs/qnx6/super_mmi.c
@@ -63,6 +63,11 @@ struct qnx6_super_block *qnx6_mmi_fill_super(struct super_block *s, int silent)
goto out;
}
+ if (!fs32_to_cpu(sbi, sb1->sb_blocksize)) {
+ pr_err("invalid blocksize 0 in superblock #1\n");
+ goto out;
+ }
+
/* calculate second superblock blocknumber */
offset = fs32_to_cpu(sbi, sb1->sb_num_blocks) + QNX6_SUPERBLOCK_AREA /
fs32_to_cpu(sbi, sb1->sb_blocksize);
--
2.55.0.1082.g2b9226bbc0-goog