From nobody Mon Sep 28 10:01:00 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4629E3A1681; Mon, 24 Aug 2026 07:59:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787558391; cv=none; b=rQ4tYXrvFpSUE857RFrqz++nus43vrp20hw7hGZmVaW0yqQuULNQj7SbrXyqdz3v1K4ZHVGPl59qQ4Cj7OclPRPBG9YzRdAuKIWb5y5B/j/2/VuV/kXS5Bw+7R6cz2pmDKfCHLt9jTjNcFX4HDwG7Nc8V9ec73V7oi+QU0KxxsQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787558391; c=relaxed/simple; bh=8CgmWQgEeeQZ8J5pzC6X/sjGSAyTtZpGXePfygosudc=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=Ld4hjJqvjDxBz6YG4ZX+Cg7T908fn/gDTyjLjYXipQaXK0Go40W/WsEpGR6+6800hUHafoiwoSeaBwBnIM6V7NWlOyqpN4gMo1XZT0zMigeCok5dE/dElz+S2mG28WBNQue1JLcd0Px26AI1lqNfA+xQyn/QzwDpwvLKIpd1TDw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: c1df3e569f9111f19a56ed5b684f684d-20260824 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.19,REQID:37df7150-0b2e-4f70-994d-98dfcdb65f6e,IP:0,U RL:0,TC:0,Content:0,EDM:0,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTION: release,TS:0 X-CID-META: VersionHash:7db8b62,CLOUDID:0bbfa936c18d905bc4a511f38735a058,BulkI D:nil,BulkQuantity:0,SF:102|850|865|898,TC:nil,Content:0|15|50,EDM:-3,IP:n il,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI:0,OSA:0,AV:0,LE S:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: c1df3e569f9111f19a56ed5b684f684d-20260824 X-User: zenghongling@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 878920382; Mon, 24 Aug 2026 15:59:39 +0800 From: Hongling Zeng To: linkinjeon@kernel.org, hyc.lee@gmail.com Cc: ntfs@lists.linux.dev, linux-kernel@vger.kernel.org, zhongling0719@126.com, Hongling Zeng , stable@vger.kernel.org Subject: [PATCH] ntfs: fix memmove overlap in ntfs_new_attr_flags Date: Mon, 24 Aug 2026 15:59:35 +0800 Message-Id: <20260824075935.170457-1-zenghongling@kylinos.cn> X-Mailer: git-send-email 2.25.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When the record shrinks while the payload offsets increase (e.g., enabling compression reduces padding, making arec_size < old_arec_size, but the head= er grows by 8 bytes), moving the name first can overwrite the old mapping_pairs before they are copied. Move mapping_pairs first in this case. Since mp_ofs is derived from name_ofs, they always change in the same direction. Checking name_ofs alone is sufficient. Fixes: fc053f05ca28 ("ntfs: add reparse and ea operations") Cc: stable@vger.kernel.org Signed-off-by: Hongling Zeng Reviewed-by: Hyunchul Lee --- fs/ntfs/ea.c | 33 +++++++++++++++++++++++++++------ 1 file changed, 27 insertions(+), 6 deletions(-) diff --git a/fs/ntfs/ea.c b/fs/ntfs/ea.c index 534f7efaf128..c836d33ab0d3 100644 --- a/fs/ntfs/ea.c +++ b/fs/ntfs/ea.c @@ -729,15 +729,36 @@ static int ntfs_new_attr_flags(struct ntfs_inode *ni,= __le32 fattr) old_arec_size =3D le32_to_cpu(a->length); =20 /* - * Move payloads before shrinking the record. Otherwise resizing moves + * Move payloads before shrinking the record. Otherwise resizing moves * the following attribute over the old payload before it can be copied. + * + * When offsets increase, move mapping_pairs first to avoid name + * overwriting the start of mapping_pairs. */ if (arec_size < old_arec_size) { - if (a->name_length && name_ofs !=3D old_name_ofs) - memmove((u8 *)a + name_ofs, (u8 *)a + old_name_ofs, - a->name_length * sizeof(__le16)); - if (mp_ofs !=3D old_mp_ofs) - memmove((u8 *)a + mp_ofs, (u8 *)a + old_mp_ofs, mp_size); + if (name_ofs > old_name_ofs) { + /* Payload offsets increased: move mapping pairs first. */ + if (mp_ofs !=3D old_mp_ofs) + memmove((u8 *)a + mp_ofs, + (u8 *)a + old_mp_ofs, + mp_size); + if (a->name_length && name_ofs !=3D old_name_ofs) + memmove((u8 *)a + name_ofs, + (u8 *)a + old_name_ofs, + a->name_length * + sizeof(__le16)); + } else { + /* Payload offsets decreased or unchanged: move name first. */ + if (a->name_length && name_ofs !=3D old_name_ofs) + memmove((u8 *)a + name_ofs, + (u8 *)a + old_name_ofs, + a->name_length * + sizeof(__le16)); + if (mp_ofs !=3D old_mp_ofs) + memmove((u8 *)a + mp_ofs, + (u8 *)a + old_mp_ofs, + mp_size); + } } =20 err =3D ntfs_attr_record_resize(ctx->mrec, a, arec_size); --=20 2.25.1