[PATCH] jfs: reject external xattrs larger than their extent

From: sungbyeongchan

Date: Sun Oct 04 2026 - 08:51:46 EST


The external extended-attribute descriptor contains both a logical byte
count and an allocated extent length. ea_read() trusts the logical size
when filling the allocated buffer even when the extent contains fewer
bytes.

A corrupt descriptor can therefore leave the end of the buffer
uninitialized. A later getxattr operation can copy a value spanning this
unread area to userspace.

Reject external attribute lists whose logical size exceeds the capacity
represented by the allocated extent. KMSAN reproduced the uninitialized
read on three boots. Size-equals-capacity and patched controls completed
without a report.

Signed-off-by: sungbyeongchan <tjdqudcks0424@xxxxxxxxx>
---
fs/jfs/xattr.c | 4 ++++
1 file changed, 4 insertions(+)

diff --git a/fs/jfs/xattr.c b/fs/jfs/xattr.c
index 11d7f74d207be..25f82ca829574 100644
--- a/fs/jfs/xattr.c
+++ b/fs/jfs/xattr.c
@@ -370,6 +370,10 @@ static int ea_read(struct inode *ip, struct jfs_ea_list *ealist)
jfs_error(sb, "nbytes is 0\n");
return -EIO;
}
+ if ((u64)nbytes > (u64)lengthDXD(&ji->ea) << sb->s_blocksize_bits) {
+ jfs_error(sb, "EA size exceeds extent capacity\n");
+ return -EIO;
+ }

/*
* Figure out how many blocks were allocated when this EA list was
--
2.43.0