[PATCH v2 0/2] ntfs: fix two kmap_local bugs on 32-bit kernels

From: Karl Mehltretter

Date: Tue Oct 06 2026 - 00:53:28 EST


Two kmap_local bugs in the mount path of fs/ntfs. Both only show on
32-bit kernels with HIGHMEM, where kmap_local_folio() hands out fixmap
slots from a per task stack of 16 entries. multi_v7_defconfig enables
both NTFS_FS and HIGHMEM, so the stock 32-bit ARM configuration is
affected.

Patch 1: check_mft_mirror() unmaps pointers that were advanced past the
end of the page. On 32-bit ARM this clears the wrong fixmap entry and
the mount dies with a BUG a few calls later. syzkaller found it on a
multi_v7_defconfig kernel. A fresh mkntfs volume reproduces it on the
first mount.

Patch 2: ntfs_check_logfile() maps the same page once per loop
iteration and unmaps it once, so a mount leaves three entries on the
stack of the mounting task. After one mount the CPU it ran on can no
longer be taken offline. A process that mounts ntfs volumes five times
hits the BUG_ON() in kmap_local_idx_push(). x86-32 also warns when
mount(2) returns.

The two fixes are independent of each other. Patch 2 was tested on top
of patch 1. Both were tested on 32-bit ARM and x86-32 in QEMU. Details
are below the --- line of each patch.

Changes in v2:
- v1 carried an older copy of patch 2 as a second 2/2 by mistake. The
patches are unchanged.

v1:
https://lore.kernel.org/r/20261006043810.5393-1-kmehltretter@xxxxxxxxx/

Karl Mehltretter (2):
ntfs: fix kunmap_local() of advanced pointers in check_mft_mirror()
ntfs: fix kmap_local leak in ntfs_check_logfile()

fs/ntfs/logfile.c | 11 ++++++-----
fs/ntfs/super.c | 20 +++++++++++---------
2 files changed, 17 insertions(+), 14 deletions(-)


base-commit: 551c722f40809618230001baccf219193e22fc5a
--
2.53.0