[PATCH 6.1.y 3/4] fs/ntfs3: fix KMSAN uninit-value in ni_create_attr_list
From: Nikita Nagornyi
Date: Thu Oct 01 2026 - 07:47:00 EST
From: Nirbhay Sharma <nirbhay.lkd@xxxxxxxxx>
[ Upstream commit 5f33da04e6ceee849e76e6592cc283c72fef7af9 ]
The call to kmalloc() to allocate the attribute list buffer is given a
size of al_aligned(rs). This size can be larger than the data
subsequently copied into the buffer, leaving trailing bytes uninitialized.
This can trigger a KMSAN "uninit-value" warning if that memory is
later accessed.
Fix this by using kzalloc() instead, which ensures the entire
allocated buffer is zero-initialized, preventing the warning.
Reported-by: syzbot+83c9dd5c0dcf6184fdbf@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=83c9dd5c0dcf6184fdbf
Signed-off-by: Nirbhay Sharma <nirbhay.lkd@xxxxxxxxx>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@xxxxxxxxxxxxxxxxxxxx>
[ Backport to 6.1.y: 6.1.y's ni_create_attr_list() uses a `goto out` cleanup
convention rather than upstream's direct returns, so only kmalloc -> kzalloc
was applied; the surrounding return/error path was left as is. ]
Signed-off-by: Nikita Nagornyi <nagornyi@xxxxxxxxx>
(cherry picked from commit 5f33da04e6ceee849e76e6592cc283c72fef7af9)
---
fs/ntfs3/frecord.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/ntfs3/frecord.c b/fs/ntfs3/frecord.c
index 17559fca5984..c9d0947651c4 100644
--- a/fs/ntfs3/frecord.c
+++ b/fs/ntfs3/frecord.c
@@ -819,7 +819,7 @@ int ni_create_attr_list(struct ntfs_inode *ni)
* Skip estimating exact memory requirement.
* Looks like one record_size is always enough.
*/
- le = kmalloc(al_aligned(rs), GFP_NOFS);
+ le = kzalloc(al_aligned(rs), GFP_NOFS);
if (!le) {
err = -ENOMEM;
goto out;
--
2.50.1