From nobody Mon Aug 24 11:02:53 2026 Received: from sxplsmtpa04-01.prod.sxb1.secureserver.net (sxplsmtpa04-01.prod.sxb1.secureserver.net [188.121.53.2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 393533D332B for ; Wed, 5 Aug 2026 17:59:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=188.121.53.2 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785952773; cv=none; b=FjgxkCunc8nvURuMsTjBHdBLMMO/xh2ma0p1iubBERXxI7TraVSqtw+mhih7EFAK2cDeZBmdg51sQHnJLu8dOwFddHhEawcGQbqwXW9kW3mEIVi/uDAlUOd/uQJDW+IL3QlwHTqAmMKcqNEBXFXaNqm/sBHpLrDTiESX40mp/cQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785952773; c=relaxed/simple; bh=vY96WaQxCNuOOI1rWo4w2EQGLMronEAXfDTlhF1uJ9Y=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=H1ODJ5ua6o9Gn4A+BZmg7XxxtO470CeBTkZbK/9RzxX1DfTuj+ssIKwZh4jc+RREp4HvlW/3XY+w5vwfBoUxr+om68sNLq7CSRpzsNcuUbD7U1z/TOtzk7TC2JuFk/Bhk6zrurtYc1M6MgYwyvOuca0X7TQfxo9oIHZdXPaZLww= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=squashfs.org.uk; spf=pass smtp.mailfrom=squashfs.org.uk; dkim=pass (2048-bit key) header.d=secureserver.net header.i=@secureserver.net header.b=Se5YYRLL; dkim=pass (2048-bit key) header.d=squashfs.org.uk header.i=@squashfs.org.uk header.b=Z1HwXAkq; arc=none smtp.client-ip=188.121.53.2 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=squashfs.org.uk Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=squashfs.org.uk Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=secureserver.net header.i=@secureserver.net header.b="Se5YYRLL"; dkim=pass (2048-bit key) header.d=squashfs.org.uk header.i=@squashfs.org.uk header.b="Z1HwXAkq" Received: from avalon.fritz.box ([82.69.79.175]) by :SMTPAUTH: with ESMTPA id rftPwesesgiPgrftiwtx8f; Wed, 05 Aug 2026 17:59:22 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=secureserver.net; s=secureserver2; t=1785952763; bh=DArSOp7W/HWxIy5H2xxKELQpo4FY1bvU6E+XEIcf8gw=; h=From:To:Cc:Subject:Date; b=Se5YYRLLixe6Gr9Hd9k94lgZnx3MoLYFFVpPuXCjekHsFNV2eR+PZVxzgKCE2mdvA kP6Vds009yRORKp1s7idAUrqAp0mTGsZjPFLjyfSOUdRwo5WdGiORgNe6ot5UWAfWj LBS8IFrC4qeyJRlh6AGpG11s555uNCtSxaxB+A7+tv5QGnIwao7XWjCZFzrAG4wj7g Tz+xR5b6mlBe1p2jecl11wPGQNDsDv9QgB48HZ8sKPv4ZPxuroM/vVmfClIy9BWnXH zuSEU7i49LEkZysfNDlBQk7I2kQ0j/7q05iz8ekptnFDfvGJX5jhOr5PQXgSNC5Hq0 ZzPQd1S/nWi1w== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=squashfs.org.uk; s=secureserver1; t=1785952763; bh=DArSOp7W/HWxIy5H2xxKELQpo4FY1bvU6E+XEIcf8gw=; h=From:To:Cc:Subject:Date; b=Z1HwXAkqdUtAdtZ1DWtIWefCQaUHIa4yJaYURD8M5d6gt5w/EdUa7Gl7Wy5aIjulU UnadXhZKoE8SRIigCnzlcf5tY3C9q62zGsTYHdAJCDGKwz2kftn+FpMkRkjOUsULnb ingD5ICUYd453mqRVxer8ojjC3q3f1kvl+ZnRWdm68KA4HLSkLHimYXpmg5xZhJkxh P1NtvOQrbsG/RaKRkF3RuNlFmuC+yjpaGVrM3wkzIGTdel5F3jvex6WC3pkN5JkYvQ CFfPIY4e9kI4TmNBviWDBi7mJeQRH+UxyyLyqtaWycNUsPHFCUnj/ehp+qFUbsMgu3 mUrYIqx85Jv6A== X-CMAE-Analysis: v=2.4 cv=XLyJoQhE c=1 sm=1 tr=0 ts=6a7379fa a=84ok6UeoqCVsigPHarzEiQ==:117 a=84ok6UeoqCVsigPHarzEiQ==:17 a=VwQbUJbxAAAA:8 a=pGLkceISAAAA:8 a=FXvPX3liAAAA:8 a=iOY-L8b0Odu9K5TEecYA:9 a=UObqyxdv-6Yh2QiB9mM_:22 Feedback-ID: 0408492f7b99422f8d5ca7db5331405b:squashfs.org.uk:ssnet X-SECURESERVER-ACCT: phillip@squashfs.org.uk From: Phillip Lougher To: linux-kernel@vger.kernel.org, akpm@linux-foundation.org Cc: Phillip Lougher , Yuejie Shi Subject: [PATCH v2] Squashfs: check block offset is not negative Date: Wed, 5 Aug 2026 18:59:00 +0100 Message-ID: <20260805175900.600140-1-phillip@squashfs.org.uk> X-Mailer: git-send-email 2.47.3 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CMAE-Envelope: MS4xfETSkDQrCXs/MqPYRVA+xv0JpzNX8tHHPAxfLstSYhnBtKAUfK1yWxYJmPJUT/gnK9M7EEE9xBs7GS5us05YDRp28pUtpxPTyx6MLGNWqAlk4Wq2Si1m ZYTeAOGJqKBC2GJgtvuJJftagfx8re6t2dt1xuF6tRV+HPiUDMafm+r4JYnb29EDj/Z7bt4a/UtxPUX9VN+dpU8Tglm74Ou3yOclNJJBN0Q1Ep/doZvuEw0u 3QXmeZj6I91a+XwqfElJuJBY1vqa2+451rti5duPX6t4dWIvCdqMJ/9gFn+ZcHR8zN96c110YXkZr+k3742Rwg== Content-Type: text/plain; charset="utf-8" If a negative offset is read off disk (for example the offset into the decompressed fragment block), this will cause squashfs_copy_data() to perform an out of bounds access. Fix by checking if offset is negative, and returning 0. This matches existing behaviour where an offset beyond the block returns 0 bytes copied. To trigger this out of bounds access requires a crafted Squashfs filesystem and CAP_SYS_ADMIN to mount it. Unprivileged users will not be able to mount such a filesystem, but once mounted, an unprivileged user can trigger the out of bounds access by reading the crafted file with the negative offset. Fixes: f400e12656ab ("Squashfs: cache operations") Reported-by: Yuejie Shi Closes: https://lore.kernel.org/all/20260803032735.81785-1-syjcnss@gmail.co= m/ Signed-off-by: Phillip Lougher --- fs/squashfs/cache.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/fs/squashfs/cache.c b/fs/squashfs/cache.c index 67abd4dff222..2807b80d46b7 100644 --- a/fs/squashfs/cache.c +++ b/fs/squashfs/cache.c @@ -299,7 +299,7 @@ int squashfs_copy_data(void *buffer, struct squashfs_ca= che_entry *entry, { int remaining =3D length; =20 - if (length =3D=3D 0) + if (length =3D=3D 0 || offset < 0) return 0; else if (buffer =3D=3D NULL) return min(length, entry->length - offset); --=20 2.47.3