Forwarded: [PATCH v1] Testing for a slub out of bounds and uaf

From: syzbot

Date: Sat Oct 03 2026 - 09:08:23 EST


For archival purposes, forwarding an incoming command email to
linux-kernel@xxxxxxxxxxxxxxx, syzkaller-bugs@xxxxxxxxxxxxxxxx.

***

Subject: [PATCH v1] Testing for a slub out of bounds and uaf
Author: nsvatoslav515@xxxxxxxxx

#syz test

Signed-off-by: Svyatoslav Nikolenko <nsvatoslav515@xxxxxxxxx>
---
fs/ecryptfs/keystore.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)

diff --git a/fs/ecryptfs/keystore.c b/fs/ecryptfs/keystore.c
index 51651314b7a6..256b7e317ea8 100644
--- a/fs/ecryptfs/keystore.c
+++ b/fs/ecryptfs/keystore.c
@@ -738,6 +738,20 @@ ecryptfs_write_tag_70_packet(char *dest, size_t *remaining_bytes,
goto out_free_unlock;
}

+ struct user_key_payload *ukp = user_key_payload_locked(auth_tok_key);
+ if (!ukp || ukp->datalen < sizeof(struct ecryptfs_auth_tok)) {
+ printk(KERN_ERR "Error key payload too small\n");
+ rc = -EINVAL;
+ goto out_free_unlock;
+ }
+
+ if (s->auth_tok->token.password.session_key_encryption_key_bytes >
+ sizeof(s->auth_tok->token.password.session_key_encryption_key)) {
+ printk(KERN_ERR "Error FNEK key size too large\n");
+ rc = -EINVAL;
+ goto out_free_unlock;
+ }
+
md5(s->auth_tok->token.password.session_key_encryption_key,
s->auth_tok->token.password.session_key_encryption_key_bytes,
s->hash);
--
2.47.3