From nobody Mon Aug 24 12:07:52 2026 Received: from sxplsmtpa04-14.prod.sxb1.secureserver.net (sxplsmtpa04-14.prod.sxb1.secureserver.net [188.121.53.148]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D677838C42A for ; Fri, 7 Aug 2026 16:32:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=188.121.53.148 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786120370; cv=none; b=TC9BAw7c5H5hNY9DTvUKg/ellP1DbGlQ7UwPXIbWrMEvD0YqYrJaffGZJERiT+BYahxpHy8k/ETxSV5bhko89SG6Md2JCPKZF5XBG9HfJ6FsyPSDRjtip5hHNNAlKdFNRGkexKUVjGWga49EBXTc7XCmEXeAuf6uQiFp6Ya8jMg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786120370; c=relaxed/simple; bh=f3htXlauoMhJjS7fiR96ykwN0izDl6oEskS5P4YfBQk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=FD6dW/S5G2hrwb0MpYSxwJozZq6Z3AbBQ2ewvLzEUaL+xqiPj89YfTJlkCjII9sMWgsB8f3UBc2ZPoAYgbJOlVKVf+f1zXU0KlwegYmG/Y1tWcSX3MrZiKJZKNL1K0dskevg+00DUn2ENF5dwsS79VpNMBzobVak+K3dEC6+Qeo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=squashfs.org.uk; spf=pass smtp.mailfrom=squashfs.org.uk; dkim=pass (2048-bit key) header.d=secureserver.net header.i=@secureserver.net header.b=srjt310K; dkim=pass (2048-bit key) header.d=squashfs.org.uk header.i=@squashfs.org.uk header.b=guIZdN0y; arc=none smtp.client-ip=188.121.53.148 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=squashfs.org.uk Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=squashfs.org.uk Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=secureserver.net header.i=@secureserver.net header.b="srjt310K"; dkim=pass (2048-bit key) header.d=squashfs.org.uk header.i=@squashfs.org.uk header.b="guIZdN0y" Received: from avalon.fritz.box ([82.69.79.175]) by :SMTPAUTH: with ESMTPA id sNSPwqEhgwSdFsNSbwUcnb; Fri, 07 Aug 2026 16:30:18 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=secureserver.net; s=secureserver2; t=1786120219; bh=8kMMt2N81klV6gEzDyTGkr9oGqVzYMLtGVwEkgtVZ80=; h=From:To:Cc:Subject:Date; b=srjt310KcaAr5uUzJCafhEujuyHVzyiY7gKa73o5jpjQlQxoD+M3dKHQupI95ZmNH Uw1rWJp2SQvMnYLCuF1fnZYrWfF2XUwDFKrSe8kHbMFjPvUy1d5WfQzs5ASkcuR2QF UmKsu76Ws9sxAnYzLqFHmdrgpjLaxcAFT+nuJuWZ4XMTb3JfxZq4zDZvUbmPQkj1Bk ha6cCHRLxqMVWfJmZnhHkcdLVYrzHqD2qI0zNWAwlrTb/dHnh3hxdI3u54SmF1nY0p uTc6pcmyS9LFyEViaWUD3pD3X/gIh3N1yaHfUye6fV/x1wq50y6MNItHHTihqSqWwf SiYNRqrxnqhpg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=squashfs.org.uk; s=secureserver1; t=1786120219; bh=8kMMt2N81klV6gEzDyTGkr9oGqVzYMLtGVwEkgtVZ80=; h=From:To:Cc:Subject:Date; b=guIZdN0y5B8LTrxc+aa1Lw9Y9mq5cVgatAZ/APbkda3DhhPQyYkfeFY5xRuJfgUDM LZw7wRgt4pDqXrP+Z2Bb39se8ElnKDzv96UrqpdNAJm6uGlF75sZhasrqPKunERy39 o2fkEM3FiD3isJ8fl1E1b3YPemS1bVh6LlIO/ojfbYJ1mRZOcYUFEKRQ7RwmDFg/84 G1nXtk6ZR0HUoGqlz/toa2gVsY3paRIuP6z4/PS5dXOIALWDrucoM4H9CjE358fXMB 85hJlFCfzAw3OE8cbmN+KPsb8/4zyHCwmXAJj7tThhhLCJb7QNehgJoiLErO80/Bld Cz/uMLKKIW01g== X-CMAE-Analysis: v=2.4 cv=MfXGfZ/f c=1 sm=1 tr=0 ts=6a76081a a=84ok6UeoqCVsigPHarzEiQ==:117 a=84ok6UeoqCVsigPHarzEiQ==:17 a=VwQbUJbxAAAA:8 a=pGLkceISAAAA:8 a=FXvPX3liAAAA:8 a=iOY-L8b0Odu9K5TEecYA:9 a=UObqyxdv-6Yh2QiB9mM_:22 Feedback-ID: 5a8d117ee17b161a1aaaef183cbffce3:squashfs.org.uk:ssnet X-SECURESERVER-ACCT: phillip@squashfs.org.uk From: Phillip Lougher To: akpm@linux-foundation.org, linux-kernel@vger.kernel.org Cc: Phillip Lougher , Yuejie Shi Subject: [PATCH V3] Squashfs: check block offset is not negative Date: Fri, 7 Aug 2026 17:29:51 +0100 Message-ID: <20260807162951.672510-1-phillip@squashfs.org.uk> X-Mailer: git-send-email 2.47.3 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CMAE-Envelope: MS4xfLg7n+2367V2TomL9NtrNUQFnoPMXJIWhW+2le06oYmGpYP2p7VVSxQXNLXU++HAsqPRaiUAB8s0gN/SHzbSrd/hSehGrC0E5EeroV5k6cMEQLL2nZNF WYrSiuwVfh9bjoUx9L4KD7ue/WPmOmGNeI4h17+wyYxRV1qeY7WBxursjwGitxdYTv2QS295/7v9DGb+6kZjuBoX6j0ZFPEeVWjo9LObANoIUPDzT+YUc4wd UnMxMY/XgggtHnKzU7HbwJus6gFg264qYwUTzNzNIvkHhrSK0HwZkoF/WkkMQncHV3J1yCBPYp1ugYsGIae8gA== Content-Type: text/plain; charset="utf-8" If a negative offset is read off disk (for example the offset into the decompressed fragment block), this will cause squashfs_copy_data() to perform an out of bounds access. Fix by checking if offset is negative, and returning 0. This matches existing behaviour where an offset beyond the block returns 0 bytes copied. To trigger this out of bounds access requires a crafted Squashfs filesystem and CAP_SYS_ADMIN to mount it. Unprivileged users will not be able to mount such a filesystem, but once mounted, an unprivileged user can trigger the out of bounds access by reading the crafted file with the negative offset. Fixes: f400e12656ab ("Squashfs: cache operations") Reported-by: Yuejie Shi Closes: https://lore.kernel.org/all/20260803032735.81785-1-syjcnss@gmail.co= m/ Signed-off-by: Phillip Lougher --- V3: add base-commit: trailer --- fs/squashfs/cache.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/fs/squashfs/cache.c b/fs/squashfs/cache.c index 67abd4dff222..2807b80d46b7 100644 --- a/fs/squashfs/cache.c +++ b/fs/squashfs/cache.c @@ -299,7 +299,7 @@ int squashfs_copy_data(void *buffer, struct squashfs_ca= che_entry *entry, { int remaining =3D length; =20 - if (length =3D=3D 0) + if (length =3D=3D 0 || offset < 0) return 0; else if (buffer =3D=3D NULL) return min(length, entry->length - offset); base-commit: 075b74841bd0065a3bda3440873c747938e69b68 --=20 2.47.3