Re: [PATCH] drbd: reject an out-of-range offset when decoding a compressed bitmap
From: Philipp Reisner
Date: Tue Oct 06 2026 - 03:49:24 EST
On Tue, Oct 06, 2026 at 03:57 UTC, Yehyeong Lee wrote:
> recv_bm_rle_bits() decodes a run-length-encoded bitmap from the peer and
> accumulates the bit position s across the runs. The upper bound
> (e >= c->bm_bits) is only checked in the branch taken for a set-bits
> (toggle) run, so a clear run advances s with no check at all.
Thanks for the report and the analysis, this is correct.
> + if (s > c->bm_bits) {
> + drbd_err(peer_device, "bitmap overflow (s:%lu) while decoding bm RLE packet\n", s);
> + return -EIO;
> + }
Checking only after the loop is not sufficient, though. A single VLI
code decodes to a run length of up to 2^56 + some, and one compressed
bitmap packet can carry a few hundred such codes.
Please check every run right after decoding it, before s is advanced:
if (rl > c->bm_bits - s) {
drbd_err(...);
return -EIO;
}
That keeps s <= c->bm_bits throughout, so neither s nor e can wrap,
and since rl >= 1 it also implies e < c->bm_bits for set runs.
Could you send a v2 along those lines?
Best regards,
Philipp