Forwarded: [PATCH v1] Testing for a slub out of bounds
From: syzbot
Date: Sat Oct 03 2026 - 07:07:01 EST
For archival purposes, forwarding an incoming command email to
linux-kernel@xxxxxxxxxxxxxxx, syzkaller-bugs@xxxxxxxxxxxxxxxx.
***
Subject: [PATCH v1] Testing for a slub out of bounds
Author: nsvatoslav515@xxxxxxxxx
#syz test
Signed-off-by: Svyatoslav Nikolenko <nsvatoslav515@xxxxxxxxx>
---
fs/ecryptfs/keystore.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/fs/ecryptfs/keystore.c b/fs/ecryptfs/keystore.c
index 51651314b7a6..bd3e025899f7 100644
--- a/fs/ecryptfs/keystore.c
+++ b/fs/ecryptfs/keystore.c
@@ -737,6 +737,12 @@ ecryptfs_write_tag_70_packet(char *dest, size_t *remaining_bytes,
"password tokens\n", __func__);
goto out_free_unlock;
}
+ if (s->auth_tok->token.password.session_key_encryption_key_bytes >
+ sizeof(s->auth_tok->token.password.session_key_encryption_key)) {
+ printk(KERN_ERR "Error FNEK key size too large\n");
+ rc = -EINVAL;
+ goto out_free_unlock;
+ }
md5(s->auth_tok->token.password.session_key_encryption_key,
s->auth_tok->token.password.session_key_encryption_key_bytes,
--
2.47.3