From nobody Sat Jul 25 04:54:17 2026 Received: from mail-pl1-f177.google.com (mail-pl1-f177.google.com [209.85.214.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 311F637C10A for ; Fri, 17 Jul 2026 16:56:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.177 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784307419; cv=none; b=cUSQ8mjL9xb/TNqmf8NXmRqacTNUheQMiekobfQ9qbH3iGPQ3SMmRnNPcxYizY3OZhF1yZglluxT6CgtfchMMzdlTr7GMQ2a2a69+vQxgDP62uSWwYp3S3Dft1l1x0PMwVRz9vVJjoLaP40UtIWKnJtQUwhlyvFKfQ1Tq8AdxoY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784307419; c=relaxed/simple; bh=RscQNZstiVa4MqUFlplLktroQovjFGkf+cEGG8/lA7Q=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=hkM0ZSbo/xNbRyv1h5I3srWoc2tU0Bm6ZN7bshwU3fF9OnWcMG69BHjoR4qAubuibWYgcyEJweysqBeUin0MH7blN9y2hanVl2SZrDjDlKlyQlinNO6PqXxMv/eGKMIfyCizmlytrQd5Qx/c89FeunHLQkJgH39EBA1XXz0zkaw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=O32VQYe5; arc=none smtp.client-ip=209.85.214.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="O32VQYe5" Received: by mail-pl1-f177.google.com with SMTP id d9443c01a7336-2cce6a0c9c3so73764105ad.1 for ; Fri, 17 Jul 2026 09:56:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784307417; x=1784912217; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=630Nymhk79OC7oRXP5aVD/h9vdOnis4FUjXTJXEAOQ8=; b=O32VQYe5QbE6Bi3XVyhiJSTCMVzBzlypPDB/a98KwaKwkt4uSFi412DJf7RXdvLAEg VzoDvofg899tKPBGKpP2dOfd1jYGNDSuvJoRSuHKOG/jaBd+WnMtqptB5i1WOrHzjNRs Ffwus2M9/+vjolmc0ee3JBRG0idwpUTG4h2avEd8UYR+ls40TLdj31UhVlmJBiKyTkB7 1kMWYWaFHbOetLhyM4u5CtquY80nJKnoxAEhMNu+jkGSYDVyxRsb+fQAhYFL4z7/N4Nj /m/nAtSz0qCw4SgEVZZG8UkHiJoFeITUmKYK693pVKuXbIY3Ybzye1izuI8e3Lqortwc 4+kw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784307417; x=1784912217; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=630Nymhk79OC7oRXP5aVD/h9vdOnis4FUjXTJXEAOQ8=; b=efko+sb15XRt1PMsjGykIeQRWxgliR3zqqoQ8qDiNoMwnj9MGpkgEw2vlyRVIeEMB5 z9uhVejqdxBib04H4hOXwv0T0+aSbUC/7741Ow/b8Ey93uLQIFuLS0hUBBSlXm5zFflm PNfaSIMYpEXbO18hvToxehgmkmM9Zf5L5b6ZuyiLak9Fr2RoAxHh58s4mvMeEUQHc2dX MzpArAchfQjpeaSomzdoP/zij5l9A7IH8iO49IkGhJmR2C02TDPjKt0ohuvAFX4ch7bi /99+AIEGWAOmbsHGqcOesTOsQfLAL3GiIDQuj+DW9lLkiNbRShx25TFyx54HX9yQbNKH qTTg== X-Forwarded-Encrypted: i=1; AHgh+RoXBB2aPxppru5VYCvPia4eXvO0SXpJIhwpRSaaIyhQYvaor6i8YykdyEWefOJg5rPnxcrZHinfoxhwSoo=@vger.kernel.org X-Gm-Message-State: AOJu0YyFRhPKdA/DBgjlqROLkWjW6y5aDyK+I8US7VMRN+RYxVIw7BQ9 WHaGFU9ntrKiMtuQHrtP56S4uXv/KTpR/+Sitak/H2TNrDY461CVj4+b X-Gm-Gg: AfdE7cnvwJQWS2oOwJ1K7LXfdz/u0lTRzeLwU9Z+9iBUcMYh68QTGF/+oIhC2ysued5 YGToyp9XG2gDfvxT/L8e4gvF8v/OtFiOXMh1tmuVswk7bW20PjglFjsjPRqxOy3O9Y9ht8yiHQl WRsR5hx+P6ojJRBfy9gXVk51t9b80fZnMAhi7a7/bF12Im1nFpmqVjycZH0SLiSnokcuBuHb5Op n6qmRKoYaKE/W/SgCJJUcITz0mYB1ixRAlDLzz5/kDApZ8USR2r43rwGvuzMCnlFr23oS4p2PcR mLzI8HvQoBicDGoQzEg9x1QYWQyaZ5oNhbJJgffPYywWLFq7NNfpX6o2Z3M0sEo8MAI5k2xgyYa QXO+lw2uahmELI1ILj99tBoPYI2eYu8T7NL8vQO5Jr4BISjzicaTXXXAPWpN0EJVYvGu5BV0XnM DJMGzVjCqwbrEdRCkhgd7oBfBe1YyPfzd/t9dHa5muWi7anMPR9Rxt3BUm X-Received: by 2002:a17:903:2c47:b0:2c9:cf41:adf9 with SMTP id d9443c01a7336-2cf34a822c8mr38902835ad.47.1784307417400; Fri, 17 Jul 2026 09:56:57 -0700 (PDT) Received: from carrot.taila25129.ts.net (madb688455.ap.nuro.jp. [219.104.132.85]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf3448fb2csm15269625ad.12.2026.07.17.09.56.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 09:56:56 -0700 (PDT) From: Ryusuke Konishi To: Viacheslav Dubeyko Cc: linux-nilfs , LKML , David Lee Subject: [PATCH] nilfs2: prevent out-of-bounds read in super root block parsing Date: Sat, 18 Jul 2026 01:56:21 +0900 Message-ID: <20260717165654.151990-1-konishi.ryusuke@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: David Lee super-root inode metadata size is trusted before nilfs_read_inode_common(). Reject super-root inode sizes whose computed on-disk footprint exceeds the filesystem block size. This prevents malformed filesystem images from making nilfs_read_inode_common() read past the end of the super-root block. [ryusuke: clarify the commit title] Fixes: 8a9d2191e9f4 ("nilfs2: operations for the_nilfs core object") Signed-off-by: David Lee Assisted-by: Codex:gpt-5.5 Signed-off-by: Ryusuke Konishi --- Hi Viacheslav, please apply this for the next cycle. As described, this prevents out-of-bounds memory access that could occur with a tampered file system image. Thanks, Ryusuke Konishi fs/nilfs2/the_nilfs.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/fs/nilfs2/the_nilfs.c b/fs/nilfs2/the_nilfs.c index 7b23e373a106..f3805e7aabeb 100644 --- a/fs/nilfs2/the_nilfs.c +++ b/fs/nilfs2/the_nilfs.c @@ -461,6 +461,12 @@ static int nilfs_store_disk_layout(struct the_nilfs *n= ilfs, nilfs->ns_inode_size); return -EINVAL; } + if (NILFS_SR_BYTES(nilfs->ns_inode_size) > nilfs->ns_blocksize) { + nilfs_err(nilfs->ns_sb, + "too large inode size for super root: %d bytes", + nilfs->ns_inode_size); + return -EINVAL; + } =20 nilfs->ns_first_ino =3D le32_to_cpu(sbp->s_first_ino); if (nilfs->ns_first_ino < NILFS_USER_INO) { --=20 2.43.0