[PATCH] fs/qnx6: reject zero block size in MMI superblock

From: Sahaj Chaudhari

Date: Thu Oct 08 2026 - 07:24:16 EST


A malformed MMI superblock may specify a zero block size.
qnx6_mmi_fill_super() divides by this value while calculating the
second superblock offset, before sb_set_blocksize() rejects invalid
sizes. Reject zero before the division so mounting the malformed
image fails through the existing cleanup path.

Reported-by: syzbot+6a0633f11d3fb88860bf@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=6a0633f11d3fb88860bf
Signed-off-by: Sahaj Chaudhari <sahaj123.sc@xxxxxxxxx>
---
fs/qnx6/super_mmi.c | 4 ++++
1 file changed, 4 insertions(+)

diff --git a/fs/qnx6/super_mmi.c b/fs/qnx6/super_mmi.c
index b8afb6f388b29..960ca68207d61 100644
--- a/fs/qnx6/super_mmi.c
+++ b/fs/qnx6/super_mmi.c
@@ -65,6 +65,10 @@ struct qnx6_super_block *qnx6_mmi_fill_super(struct super_block *s, int silent)
}

/* calculate second superblock blocknumber */
+ if (!fs32_to_cpu(sbi, sb1->sb_blocksize)) {
+ pr_err("invalid blocksize\n");
+ goto out;
+ }
offset = fs32_to_cpu(sbi, sb1->sb_num_blocks) + QNX6_SUPERBLOCK_AREA /
fs32_to_cpu(sbi, sb1->sb_blocksize);

--
2.43.0