From nobody Sat Jul 25 22:32:27 2026 Received: from mail-pj1-f42.google.com (mail-pj1-f42.google.com [209.85.216.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7886A381E87 for ; Sun, 12 Jul 2026 23:41:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.42 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783899721; cv=none; b=O0Hn5E6YHSZQkjXaB3vpMhoTJeJDuLLPwXoZLwbsi3a6A3OUJWU9wgXtpDQZKV7GJ8wkntANFyaTjAlf9o9hR2XNSccNjCybwsIhhszkhzkMSTrG+JLP5c1hBuOvgyFVtVXqlaz6pO8rScIn/kPhgg/pWc36sOKRmODNoYPQS04= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783899721; c=relaxed/simple; bh=Gus8jbYJkmsWK1Td00YMeQsUjHCsejAnbeRtFN2Wo1Y=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=V6JGAjEZIImPgF2doLFhHtqlBVraaZpj9gj9nyhczWppJuMD2JdjkrwSMr1TiliaUWPDona+WOBmoKEl8s+FGfsshN6i+3ST2+i9iSySZcDpZpTZGd77mGYN1F43JK6YIyVtkB5htmGFm3nGOHPom02SlwyIAxARwrh1wIaKlqg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=asu.edu; spf=pass smtp.mailfrom=asu.edu; dkim=pass (2048-bit key) header.d=asu.edu header.i=@asu.edu header.b=as9PKvLV; arc=none smtp.client-ip=209.85.216.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=asu.edu Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=asu.edu Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=asu.edu header.i=@asu.edu header.b="as9PKvLV" Received: by mail-pj1-f42.google.com with SMTP id 98e67ed59e1d1-38dcbade417so930083a91.1 for ; Sun, 12 Jul 2026 16:41:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=asu.edu; s=google; t=1783899719; x=1784504519; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=HEoxedDY+CxIxJPNu4gqzihdjaJt6oxwDBr+q3d3y1M=; b=as9PKvLV87yWxszqOIQyNlykg+ZkI9fdGTkQEDSRRJEPWm5zKAO5U2rJuiTnhBWwGz 1tujJEw3yzF3ykUefIYfnbsn4l8jMPRitgH30nzNwN0f5whieKutI6r4hmZjeQrkKkQT ImtLvbZI77+f7Be6zdhKnuTGbqjIqdulF257gO3OJsO2tFBa6CQEgdK8/G3/81i1/oBo qiv3QOiyW2QTsCQPz6ifFYRUMloBdEi3uIvO8P5adM9BzT3ydCRCR2VRb6FGxkCe9fN4 8W9fVT5ndIeBFf80n/YThWLLLYZun51OKOV8xINwSyY+uR67mxLP/7ZHM3ZXvVys8qNM jl4Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783899719; x=1784504519; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=HEoxedDY+CxIxJPNu4gqzihdjaJt6oxwDBr+q3d3y1M=; b=NvwDMYiZ+20jVt7+deNhEKyNN0QCsibIyoPQaAgkIN9j/m4+Cg2XJRsCFK2BH1rKJ7 stuVPbq+2/wB7RrTfflRD+V5Y2U8qN1PxeH0pFfETO5Xt54uIj17vaoHYETGIMLFwk8n BFEgcYmtek4LYN4+mFQ3dbUk2TXgdYTDAQNcBvAQ0yXsJdJT/O5bkltjIf7XuNVfLMWz H2x1Lz3YIiTSSzW9tUEUDn/J9YKXIcLZGqOLW8gIWygSQsZpoeT6Bb146AtupKl1wAim olwyYBfMNtbx6XFHDlSjTNdLaAI+w+RKcBBWxQB3zdyfpmDcC2hrUEvhAb0ywRkhG+Zz D3yw== X-Forwarded-Encrypted: i=1; AHgh+RqYCWMvmC7QjUMB1qkNa+HD8Aggj8HgYTgoaqOSKEDoe8/bS6oh0xx3Thn0b9+Ix4VfJv07uiAMTGhI/jQ=@vger.kernel.org X-Gm-Message-State: AOJu0YzcVHmp0/aHTvcXsOYOy4wyxG+MfIWC7bD4L2o5voRtOg+pb3Ju RH21V5fcq6+J7BQoHcIZEgS3M0d0pClYqT/gri8AgbwQ1cB7coGd4suBxpD6M7z1+w== X-Gm-Gg: AfdE7ckgN8owHC9BZVrWd2FoC7sMsJFqghuw3Umw0bcVD0iUQOmODYDe+gUXrSX2fb5 McmWFDMAZxmKek5iAMxonAvQ4KFI+JgMbExd6eQ3SeWeUrmhwKYSX6zXCawoXIKzJsETD4wBEGX PVtHR1J/dIs1GXrmOB9M4BuukEcUAy5b/R5UGLU1LBdbDPYlconnPB9AGfrx64GTWUG62ppeymy iCmIwDPbXEYcrYYyZQXMcy9C57t/CG391rWFE1ZIix0p7RT98QcmxFTNbNHR8XSOOsk037I0C3S WGrjnUNsxO6gAM9CjQ8CdUKLLHZOalPUxhtJpW0Yhz+mnv5YVox9Cb22W+TT58WjnOLwohGQ5OS Ue3DJtDuunKKNTbRqXyiDPtqXTtAMNsu6nNJv+4h+aUVUxUzLfveovxjDDfjhkzalV7zyv1AfLD nXNU6oD9af X-Received: by 2002:a17:90a:e70f:b0:387:e0cb:7ee with SMTP id 98e67ed59e1d1-38dc781ce28mr5423917a91.34.1783899718788; Sun, 12 Jul 2026 16:41:58 -0700 (PDT) Received: from p1.. ([2607:fb90:ec82:d7be:f961:4fa0:51a9:cde5]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-38a5506dee6sm5501100a91.4.2026.07.12.16.41.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 12 Jul 2026 16:41:58 -0700 (PDT) From: Xiang Mei To: Jan Kara Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Weiming Shi , Xiang Mei Subject: [PATCH] isofs: fix out-of-bounds page array access on empty zisofs block Date: Sun, 12 Jul 2026 16:41:50 -0700 Message-ID: <20260712234150.3213467-1-xmei5@asu.edu> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" zisofs_uncompress_block()'s empty-block fast path returns pcount << PAGE_SHIFT, ignoring the incoming poffset, unlike the decompression path which returns bytes produced relative to poffset. zisofs_fill_pages() uses that return to advance its page cursor, so when the zisofs block size is below PAGE_SIZE and a sub-page block leaves poffset partway into a page, a following empty block over-counts and advances pages[] one element past its end, after which "if (poffset && *pages)" reads pages[1] out of bounds. rock.c only rejects a block-size shift > 17, so a crafted "ZF" Rock Ridge record can set it below PAGE_SHIFT; the bug is reached by an ordinary read() of a compressed file on such a mounted ISO9660 image. Return the byte count relative to poffset and zero only [poffset, PAGE_SIZE) of the first page, matching the decompression path. The page-aligned case (poffset =3D=3D 0) is unaffected. BUG: KASAN: slab-out-of-bounds in zisofs_read_folio (fs/isofs/compress.c:= 290) Read of size 8 at addr ffff88800f5eac48 by task exploit/142 zisofs_read_folio (fs/isofs/compress.c:290) read_pages (mm/readahead.c:184) ... filemap_read (mm/filemap.c:2814) vfs_read (fs/read_write.c:574) __x64_sys_pread64 (fs/read_write.c:769) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) The buggy address is located 0 bytes to the right of the allocated 8-byte region in the kmalloc-8 cache Fixes: 59bc055211b8 ("zisofs: Implement reading of compressed files when PA= GE_CACHE_SIZE > compress block size") Reported-by: Weiming Shi Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Xiang Mei --- fs/isofs/compress.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/fs/isofs/compress.c b/fs/isofs/compress.c index 397568b9c7e7..3fda92358e22 100644 --- a/fs/isofs/compress.c +++ b/fs/isofs/compress.c @@ -65,12 +65,14 @@ static loff_t zisofs_uncompress_block(struct inode *ino= de, loff_t block_start, /* Empty block? */ if (block_size =3D=3D 0) { for ( i =3D 0 ; i < pcount ; i++ ) { + unsigned int off =3D i ? 0 : poffset; + if (!pages[i]) continue; - memzero_page(pages[i], 0, PAGE_SIZE); + memzero_page(pages[i], off, PAGE_SIZE - off); SetPageUptodate(pages[i]); } - return ((loff_t)pcount) << PAGE_SHIFT; + return (((loff_t)pcount) << PAGE_SHIFT) - poffset; } =20 /* Because zlib is not thread-safe, do all the I/O at the top. */ --=20 2.43.0