[PATCH] jfs: account for the dirent header and charset expansion in jfs_readdir()

From: Yogesh Gaur

Date: Tue Oct 06 2026 - 08:42:15 EST


jfs_readdir() converts each on-disk name into a struct jfs_dirent in a
PAGE_SIZE buffer, and stops filling the buffer when the next entry
might not fit:

if (((long) jfs_dirent + d->namlen + 1) >
((long)dirent_buf + PAGE_SIZE)) {

That check undercounts twice. The name is written at jfs_dirent->name,
after the 14-byte header, not at jfs_dirent. And d->namlen counts
UCS-2 characters, while jfs_strfromUCS_le() lets the codepage's
uni2char() write up to NLS_MAX_CHARSET_SIZE bytes for each one; with
iocharset=utf8 most non-ASCII characters take two or three bytes. So
an entry that passes the check can still be written past the end of
the buffer. Since commit de9f4f0b2c0f ("jfs: replace __get_free_page()
with kmalloc()") the buffer comes from kmalloc-4k and KASAN reports it:

BUG: KASAN: slab-out-of-bounds in utf32_to_utf8+0x24d/0x3d0 fs/nls/nls_base.c:111
Write of size 1 at addr ffff888039ad7000 by task syz-executor304/5946
utf32_to_utf8+0x24d/0x3d0 fs/nls/nls_base.c:111
uni2char+0x35/0xa0 fs/nls/nls_utf8.c:21
jfs_strfromUCS_le+0xd2/0x3d0 fs/jfs/jfs_unicode.c:31
jfs_readdir+0x16fd/0x33f0 fs/jfs/jfs_dtree.c:2984
The buggy address is located 0 bytes to the right of
allocated 4096-byte region [ffff888039ad6000, ffff888039ad7000)

Before that commit the same write went into whatever page followed.

Check against the worst case instead: the name starts at
jfs_dirent->name and each character can take NLS_MAX_CHARSET_SIZE
bytes, or one byte when no codepage is set. The largest entry is
then 255 * 6 + 15 bytes, so an empty buffer still always takes at
least one entry and readdir keeps making progress.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: syzbot+a2748ba908c108e7e525@xxxxxxxxxxxxxxxxxxxxxxxxx
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Yogesh Gaur <yogeshgaur.83@xxxxxxxxx>
---
Built with W=1 only; not runtime-tested.

fs/jfs/jfs_dtree.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/fs/jfs/jfs_dtree.c b/fs/jfs/jfs_dtree.c
index 8ce6e4458cc2..d930e577a496 100644
--- a/fs/jfs/jfs_dtree.c
+++ b/fs/jfs/jfs_dtree.c
@@ -2712,6 +2712,8 @@ int jfs_readdir(struct file *file, struct dir_context *ctx)
{
struct inode *ip = file_inode(file);
struct nls_table *codepage = JFS_SBI(ip->i_sb)->nls_tab;
+ /* most bytes one on-disk character can turn into in jfs_dirent */
+ int max_charlen = codepage ? NLS_MAX_CHARSET_SIZE : 1;
int rc = 0;
loff_t dtpos; /* legacy OS/2 style position */
struct dtoffset {
@@ -2910,9 +2912,10 @@ int jfs_readdir(struct file *file, struct dir_context *ctx)

d = (struct ldtentry *) & p->slot[stbl[i]];

- if (((long) jfs_dirent + d->namlen + 1) >
+ if (((long)jfs_dirent->name +
+ d->namlen * max_charlen + 1) >
((long)dirent_buf + PAGE_SIZE)) {
- /* DBCS codepages could overrun dirent_buf */
+ /* the converted name might not fit */
index = i;
overflow = 1;
break;
--
2.55.0.windows.5