From nobody Mon Sep 28 11:39:33 2026 Received: from mail-ej1-f42.google.com (mail-ej1-f42.google.com [209.85.218.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5033F3EC82B for ; Sat, 22 Aug 2026 14:33:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.42 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787409223; cv=none; b=h+hLhqfxDGY5p0mvFcN/YtmTUcR45M8OXrpR0sbm44g9+7MullJbz3KzPnRGIavVOCM85NHaPP1C9NPuF6245U5apGbaUvzmaOZ2Rgs8dPOAnMUx0BX409dp2WbjcvqHrCCKdhGXtV2D0szhcCqjjMMgW6FnZXA+Qz7gVZMxxV4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787409223; c=relaxed/simple; bh=YGXWoJ4LhhhkF7EWbP81eYh61/pNV08G4d7PwdAEWO4=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=FX2dny99RS7s/yUsOYxO5WI4MtBfvY6l4HYgaB1WXf5B1IcnW9cyi/lqnnTQyc0y08Ac/IPPzqUXi9F2b3GgRJd3iExpiIJAcJFMvxT2JXB0nHT4P8lcJ57UBD6GifruFmmmAHAUSZff88myDroA/ay23IcuF2z48h5INPFL3R4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=SbfRkvK6; arc=none smtp.client-ip=209.85.218.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="SbfRkvK6" Received: by mail-ej1-f42.google.com with SMTP id a640c23a62f3a-c167aa9500dso308864866b.3 for ; Sat, 22 Aug 2026 07:33:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787409218; x=1788014018; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/FlxrXjQiw5bnwrdA7FzNpOb5hdE68uhQMeRmlYnIxQ=; b=SbfRkvK6GjbkzxcKu1MzCjYv/ng3EyqKSr4Iqn9crkFP+MynNlhjpI+6Zupsp/EXIV Y/S81JNvSimbru4VDwRnCE8Om6WEOLV2nwaGwI7Jak3lzJuIbwbmCW+HeBHnVlnqHlH0 NgczhhZ5Ti+YsmHze6lVxOWkO1L3qls9iXJ6jT5fyz8u5DtLrEE2F2jiCZf23ZI0lMwM AefZsQK8NsUZLW4jT0degFgo05zy3UW8FuYG1O47l5m9n5fadOCvY5IPUqvi8GUCOAf6 FgL5Dykm7z6qM4Idr44JuELES+M8Pjp+T5uUWqnhKENS5WErjDTeM22vatAagbjUJBcZ DGVQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787409218; x=1788014018; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/FlxrXjQiw5bnwrdA7FzNpOb5hdE68uhQMeRmlYnIxQ=; b=ARN7UqU400TYFHCpOxsFnFwPF5WIQQG57vOwFVo9bBbNv1h/UlmcMY2V+LCEiFH8TX WCv96WOELdd0s+BYNAgjHtjDluYb/fmievf62IiyM9yjAqE724Ar2ZhRHEuJGATouCXb sO24TOjEAEr3gls/T49/p7dt0TSCrxH1aR4sJsGoyOEvaXzIExd1ZXA4fLyTDU9bCFJc dpF5wE4P21lgaFaUUILoeOj4bq9yqJUUQyJlOIAM7UMcr4bGPU/pjY0PcYMqAAyBLIPF n8Yrp3giSUiZO16Qj7dq5Cm4SrlTGUDZ2vSJYpFUh+LfEm+gQbzWKDvhly9SfOjkD9oB de5Q== X-Forwarded-Encrypted: i=1; AHgh+RqXLXjsff9RILyCXMx6RHPogi8ZAaZ9lUMYF8Hc8m2Mi1bJdcR+9o0XKapMkeqe5Jl7gZyPNQ2n7ttFZ6s=@vger.kernel.org X-Gm-Message-State: AFuF++n9BimvvXlUFjC7wmzILq6vieUCH5LxqbNSGk8o8K9wxEvw3qUj jELSMca5DdN1cu/popvxhX+huXD2yORhBH0YaLl/oXqA+WidfTzC7oQw X-Gm-Gg: AR+sD12kAbjTqQsRObi7Tm18RrHBQjKxssdSSwmkfipn51wR8lVgcQ5DNYi/gocGNNc UflsvysXIwXQOtoJrhNQLTp8IXQbzK+WZx1E1RrOSWLtPmykGE/V0nUeutA8Vp31G6o31Ay31Q5 59s+Ec8H7IdDxMJiyCGWGPQ9mQSvn/KBx5VFNzjikgbDyI5hR0t2zGcGagODOYkwVAQ7SMPVnE3 3jpQeMfr0zznm7Wc79l2DJabuDQW6nOVnp9xKdeqjQzhyrgiHkryPRop7xEn1ZqPxK0gFa+SDm6 GcfChvHkS7tPONWeKODr5jc+82IZoySQFAB2POkTXFjNQxO1voY2jMClTTTHUy9sFJOzLxrnRbK oxzrH4JMMZOIbVXkV+OIf3fiGe3ZtZl80me6vrqIviYPA8qRkGbBIJxeqnr9cXEBSMzNQxZIXwx F223uzj4P+T/zbYa/uG9O140+++c6AquFsQVfxszWA6ThIAoI4QiUroa0tNJEZrcg2hoUTlt027 lQUz1NdlS+3ZQryNUkFMKO4uPn/4MJvkdghDTWBL6UzbHpNmB1VpNv6wajwcITZfrGWv14tBjU+ OwGlDSV1A6d17lFeIcP8RtJmNx2DHmcSsnCjQz4VDc++DBb/IR1tv2yjUA01byfhW20eVlZY43Z LJ84= X-Received: by 2002:a17:907:9603:b0:c07:43ed:1b3e with SMTP id a640c23a62f3a-c2469f9a365mr1597208466b.0.1787409217798; Sat, 22 Aug 2026 07:33:37 -0700 (PDT) Received: from localhost.localdomain (dynamic-2a02-3100-a0f5-8c01-3de3-cd62-aa6f-2fb0.310.pool.telefonica.de. [2a02:3100:a0f5:8c01:3de3:cd62:aa6f:2fb0]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c24967459aesm326597666b.48.2026.08.22.07.33.36 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sat, 22 Aug 2026 07:33:37 -0700 (PDT) From: Karl Mehltretter To: Phillip Lougher Cc: Karl Mehltretter , Andrew Morton , linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH 1/2] squashfs: fix fragment index table sizing overflow on 32-bit Date: Sat, 22 Aug 2026 16:33:27 +0200 Message-Id: <20260822143328.68867-2-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260822143328.68867-1-kmehltretter@gmail.com> References: <20260822143328.68867-1-kmehltretter@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" SQUASHFS_FRAGMENT_BYTES() multiplies the on-disk fragment count (an unsigned int) by sizeof(struct squashfs_fragment_entry), a size_t. On a 32-bit kernel that product is 32-bit and can wrap. squashfs_read_fragment_index_table() sizes the fragment index table from it, but squashfs_frag_lookup() bounds the fragment number against msblk->fragments, the unwrapped superblock value. The two disagree: an image declaring 0x10000001 fragments wraps the product to 16, so a single index entry is allocated, yet the lookup still accepts fragment 0x0fffffff: if (fragment >=3D msblk->fragments) return -EIO; block =3D SQUASHFS_FRAGMENT_INDEX(fragment); ... start_block =3D le64_to_cpu(msblk->fragment_index[block]); block is then 524287 and the read lands ~4MB past an 8-byte allocation. On a 32-bit build KASAN catches it when the crafted image is mounted and the file is stat'd. Cast to u64 in the macro so the multiplication is 64-bit on all targets. After conversion to index-table entries, SQUASHFS_FRAGMENT_INDEX_BYTES() is at most 64 MiB for any u32 count, so it fits both the unsigned int local and the int argument it feeds. 64-bit builds are unchanged. Fixes: ffae2cd73a9e ("Squashfs: header files") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 Signed-off-by: Karl Mehltretter --- fs/squashfs/squashfs_fs.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/fs/squashfs/squashfs_fs.h b/fs/squashfs/squashfs_fs.h index a955d9369749f..93436c7d80c97 100644 --- a/fs/squashfs/squashfs_fs.h +++ b/fs/squashfs/squashfs_fs.h @@ -136,7 +136,7 @@ static inline int squashfs_block_size(__le32 raw) =20 /* fragment and fragment table defines */ #define SQUASHFS_FRAGMENT_BYTES(A) \ - ((A) * sizeof(struct squashfs_fragment_entry)) + ((u64)(A) * sizeof(struct squashfs_fragment_entry)) =20 #define SQUASHFS_FRAGMENT_INDEX(A) (SQUASHFS_FRAGMENT_BYTES(A) / \ SQUASHFS_METADATA_SIZE) --=20 2.53.0 From nobody Mon Sep 28 11:39:33 2026 Received: from mail-ed1-f41.google.com (mail-ed1-f41.google.com [209.85.208.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9E03A3F0AA7 for ; Sat, 22 Aug 2026 14:33:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787409225; cv=none; b=n6nifRDkO5zUg6bDGsA8jeq5m4RA09vU/ku9l9ekUBnvSo1uVRDRvuotSfQRJMlXoz4O5613Z1WyEsX9a/SNi4GJO0DGA+GGgqjwc+S4kU0YHOtdeo48anpLbzll7st6QpC4G4elmVwvMViT66BF8GOmyb0MHHquPKVd8PugDhM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787409225; c=relaxed/simple; bh=O75aJsjqWRTKOyF9lF+KMK/BaLq0JLQHHNFq2vo1ctQ=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=ZQS718uW1k9FhnZwdrdK5Kk95e9+qnhKIb0Z9u42OZvib14eUyhVFMaZb+Qv+JlI8wxKQu002CVUNfQBqb+NadPr6uN3xTfrGV9DhfWbQ1mRw80GDoQ1sF/Olt/pQBZD/DtOV3kn010ux4CPbU/yV6fRoguZ0T3rZAHcSetc6cY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=JpzU4693; arc=none smtp.client-ip=209.85.208.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="JpzU4693" Received: by mail-ed1-f41.google.com with SMTP id 4fb4d7f45d1cf-6a36982a875so3090132a12.0 for ; Sat, 22 Aug 2026 07:33:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787409220; x=1788014020; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=IdHnfPP19LuCe1htvM6rTR3Vijz/0/LUnIK+qvqxgNU=; b=JpzU4693kaZxV1j04Si2uWuUMhFhqUPFtBAUksealoAlZ5p9D8oXteXXZPI0xOMhLx bkHMrl9lzlNkfTfiicwx+xf6b+2ms3E6UFJ39ZgDNsXSu6NRSTKLl1HSPcAFE2Fz2f5v vJWPpjYAK/5vb0gYUw0qpus3lQbDRAzSzYHP/rBrC9wqlhWTvcmsPlPRKEDkwOzjsK5O wzgZYIZwWyVcsIQkVXjzeNXHKGFpbd3YfyhlMuQjpPUSTWR9AeInu+NEcHqYClw9ZGd7 8c1bbayWW1gdVtrMPMG6uWDcMthqYvGEwEFTZodUe/RYkKsV/1ZU+pE2Y5tNo1SFWvHw 4pZA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787409220; x=1788014020; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=IdHnfPP19LuCe1htvM6rTR3Vijz/0/LUnIK+qvqxgNU=; b=VwlaELhuiPUfuB5j3+AAWANMvvbJe95VThqtV/+Fzg1LRd7qV2gsBLc/RjefXnpjZO NAclOvF64vnMV2pWj8/hjC7zdhq8krMIocV5Ajty++0taiC9Wt09A9+T7V6S9ldwRVHB muEGxpDhhGsHApft6ZYvwp8rb1Av/1KU1guastZgu0rQW43DfanBw1z+PXEZyBioTPeG dBHr3/3ZegRukKijbs6e/VkXDEFhDoA1ry8rCkcRbj+7ZuVAwUKR/Lw8KKNstoT8Etu+ 0uTZxyTJE50exWKyUYBkJF9Nik7oOCFAek+B/DhL/nW/tzR8VyA/YzmAVYqtp98RNOf7 f/Yw== X-Forwarded-Encrypted: i=1; AHgh+RpZrsrH+XRMTF+/EBrYH7+706yeQWZnnAN6sgAgZJ3piYAKD56V91ooOIjKK2Hk1VMvvPhdddvAvJbpSgs=@vger.kernel.org X-Gm-Message-State: AFuF++lHQ6dNC0L2F63vKPC8LOK1/QYjSJJ62bUQCW2M9ZdYxoLLYXgq Q3vdAVZoBPKsyBlIw6Z9FBkw99yjIll8Wfb+cKSHZsmlGYx+Mv2U0RwYRvfHDdXc X-Gm-Gg: AR+sD12kNDz4mZ0uoJopIgM0T2YXAbaxNk0x39cXaFHV5DVYR+HxDVO4uiGQSOSRF5a qT9fIHZvjUzrTQqD7QlPEfZEeJfy5yJsEwQtxe83CZSXAyaYvtRu/EhuIRQ21C8A/wWnxsR3OWp WwEj+Zjai2lnWh4bgPrnqYqKr2lfJ8/+54+so3St1BNsMfA7erKWT9XuqqLQGeuJ+7HGYlpTDCO TmjsLL0hHdbgxNL0b1x7L4+LFK7iTAzPaa9Na8ZyF4hZ4ZVmOGsZVo2YKIhPkfmamkBKxHWiSWe A+uc2n/gEy/yLBDQUEFom6BvWZ3xpwSFic/Zl5BSMugnHwOkAl3YCAHnuML6aiQx1Y7eozdCwX4 uD+XiOjIJ5mjgOAkcJfsIHD4qdSBkn8GK8d4dJD806mAE91b/Cbjeaweq3JEnILO5lXGvfeWSkO n/3IdyC4XmMtTVCD4yUqul7w5cl+MQTRN/zs5SiZcyx0VZQngXqOcfWaW2YEtRHluXZULIOGTVO 92KglIXpZzcYW99K4Dah9l/L6La3wIqgZgC9A0R8R5ADPTxZjR3sW3PUEe/cZYIQX4yWnFU/mdb qCdKMALhpSo1HEM3bG8bEKh45DP/UX/SZ3fHFjXm3G4lMkGxGiyTgGW8yfzsuftLafBk X-Received: by 2002:a17:906:fd81:b0:c21:35d0:f43d with SMTP id a640c23a62f3a-c246a6c52c2mr1473232666b.16.1787409219699; Sat, 22 Aug 2026 07:33:39 -0700 (PDT) Received: from localhost.localdomain (dynamic-2a02-3100-a0f5-8c01-3de3-cd62-aa6f-2fb0.310.pool.telefonica.de. [2a02:3100:a0f5:8c01:3de3:cd62:aa6f:2fb0]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c24967459aesm326597666b.48.2026.08.22.07.33.38 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sat, 22 Aug 2026 07:33:39 -0700 (PDT) From: Karl Mehltretter To: Phillip Lougher Cc: Karl Mehltretter , Andrew Morton , linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH 2/2] squashfs: make the fragment index table bounds check overflow-safe Date: Sat, 22 Aug 2026 16:33:28 +0200 Message-Id: <20260822143328.68867-3-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260822143328.68867-1-kmehltretter@gmail.com> References: <20260822143328.68867-1-kmehltretter@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" squashfs_read_fragment_index_table() checks that the table fits before the next one with: if (fragment_table_start + length > next_table) return ERR_PTR(-EINVAL); fragment_table_start comes from the superblock and is not validated before this point. A start of 2^64 - length wraps the sum to zero, so the check passes regardless of next_table and fails to reject the invalid table ordering. length then reaches kmalloc() through squashfs_read_table(). A fragment count of 0xffffffff asks for 64MB, order 14. GFP_KERNEL does not include __GFP_NOWARN, so the page allocator warns before the mount fails with -ENOMEM. With panic_on_warn, the warning panics the kernel. Compare the operands instead of adding them. id.c and export.c avoid the same wrap with an exact-size check. Keep the inequality here because a gap before the next table is still allowed. Fixes: 1cac63cc9b2f ("Squashfs: add sanity checks to fragment reading at mo= unt time") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 Signed-off-by: Karl Mehltretter --- fs/squashfs/fragment.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/fs/squashfs/fragment.c b/fs/squashfs/fragment.c index 49602b9a42e19..b46673d1077a0 100644 --- a/fs/squashfs/fragment.c +++ b/fs/squashfs/fragment.c @@ -69,9 +69,11 @@ __le64 *squashfs_read_fragment_index_table(struct super_= block *sb, /* * Sanity check, length bytes should not extend into the next table - * this check also traps instances where fragment_table_start is - * incorrectly larger than the next table start + * incorrectly larger than the next table start. Both values are read + * from the filesystem image, so compare without adding them. */ - if (fragment_table_start + length > next_table) + if (fragment_table_start > next_table || + length > next_table - fragment_table_start) return ERR_PTR(-EINVAL); =20 table =3D squashfs_read_table(sb, fragment_table_start, length); --=20 2.53.0