[PATCH 2/2] nilfs2: validate directory position after llseek in readdir
From: Ryusuke Konishi
Date: Thu Oct 08 2026 - 07:58:42 EST
From: Jake Labelle <southampton.jake.labelle@xxxxxxxxx>
nilfs_readdir() uses ctx->pos, which userspace can set to an arbitrary
value via llseek, as an offset into the directory folio and parses
whatever bytes sit there as a directory entry. A position pointing
into the middle of an entry -- or at unused bytes of a corrupted image
that the page validator never inspected -- makes dir_emit() copy up to
255 (name_len) bytes from a bogus entry, possibly reading past the end
of the folio and returning unrelated memory contents to userspace.
Snap unaligned positions onto a valid entry boundary by walking the
rec_len chain from the chunk start before parsing, as ext2 does in
ext2_validate_entry().
[ryusuke: fixed offset wrap-around in nilfs_validate_entry() and
conformed AI tag to guidelines]
Fixes: 2ba466d74ed7 ("nilfs2: directory entry operations")
Assisted-by: Claude:claude-mythos-5
Signed-off-by: Jake Labelle <southampton.jake.labelle@xxxxxxxxx>
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@xxxxxxxxx>
---
fs/nilfs2/dir.c | 34 ++++++++++++++++++++++++++++++++++
1 file changed, 34 insertions(+)
diff --git a/fs/nilfs2/dir.c b/fs/nilfs2/dir.c
index 8b53802b6ebd..7686ca9228fc 100644
--- a/fs/nilfs2/dir.c
+++ b/fs/nilfs2/dir.c
@@ -231,11 +231,27 @@ static struct nilfs_dir_entry *nilfs_next_entry(struct nilfs_dir_entry *p)
nilfs_rec_len_from_disk(p->rec_len));
}
+static inline unsigned int
+nilfs_validate_entry(char *base, unsigned int offset, unsigned int mask)
+{
+ struct nilfs_dir_entry *de = (struct nilfs_dir_entry *)(base + offset);
+ struct nilfs_dir_entry *p =
+ (struct nilfs_dir_entry *)(base + (offset & mask));
+
+ while ((char *)p < (char *)de) {
+ if (p->rec_len == 0)
+ break;
+ p = nilfs_next_entry(p);
+ }
+ return (char *)p - base;
+}
+
static int nilfs_readdir(struct file *file, struct dir_context *ctx)
{
loff_t pos = ctx->pos;
struct inode *inode = file_inode(file);
struct super_block *sb = inode->i_sb;
+ unsigned int chunk_size = nilfs_chunk_size(inode);
unsigned int offset = pos & ~PAGE_MASK;
unsigned long n = pos >> PAGE_SHIFT;
unsigned long npages = dir_pages(inode);
@@ -254,6 +270,24 @@ static int nilfs_readdir(struct file *file, struct dir_context *ctx)
ctx->pos += PAGE_SIZE - offset;
return -EIO;
}
+ /*
+ * ctx->pos comes from userspace via llseek and may point
+ * into the middle of an entry -- or at unvalidated bytes
+ * of a crafted image. offset is only nonzero here on the
+ * very first iteration (subsequent pages always start at
+ * offset 0, which -- like any chunk boundary -- is always
+ * a legitimate entry start, since no rec_len chain crosses
+ * a chunk boundary). Snap a non-chunk-aligned offset onto
+ * a real entry boundary by walking the chain from the
+ * enclosing chunk's start, as ext2 does; otherwise
+ * dir_emit() copies name_len bytes from a fake entry,
+ * reading past the end of the folio.
+ */
+ if (offset & (chunk_size - 1)) {
+ offset = nilfs_validate_entry(kaddr, offset,
+ ~(chunk_size - 1));
+ ctx->pos = ((loff_t)n << PAGE_SHIFT) + offset;
+ }
de = (struct nilfs_dir_entry *)(kaddr + offset);
limit = kaddr + nilfs_last_byte(inode, n) -
NILFS_DIR_REC_LEN(1);
--
2.53.0