number of bytes allocated for mft record should be equal to the mft record size stored in ntfs superblock as reported by syzbot, userspace might trigger out-of-bounds read by dereferencing ctx->attr in ntfs_attr_find()
Reported-and-tested-by: syzbot+aed06913f36eff9b5...@syzkaller.appspotmail.com Link: https://syzkaller.appspot.com/bug?extid=aed06913f36eff9b544e Signed-off-by: Rustam Kovhaev <rkovh...@gmail.com> --- fs/ntfs/inode.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/fs/ntfs/inode.c b/fs/ntfs/inode.c index 9bb9f0952b18..6407af7c2e4f 100644 --- a/fs/ntfs/inode.c +++ b/fs/ntfs/inode.c @@ -1810,6 +1810,12 @@ int ntfs_read_inode_mount(struct inode *vi) brelse(bh); } + if (m->bytes_allocated != vol->mft_record_size) { + ntfs_error(sb, "Incorrect mft record size [%u] in superblock, should be [%u].", + m->bytes_allocated, vol->mft_record_size); + goto err_out; + } + /* Apply the mst fixups. */ if (post_read_mst_fixup((NTFS_RECORD*)m, vol->mft_record_size)) { /* FIXME: Try to use the $MFTMirr now. */ -- 2.28.0