From nobody Mon Sep 28 12:33:02 2026 Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5745B2931C0 for ; Fri, 21 Aug 2026 14:22:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.50 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787322160; cv=none; b=A1MFnQHD7soIrCPOBlLEZu0tjFPbEkmcI4CleewMIPRU2ojQqo6xigVPP4RaDdJ6zts7KE5qMHu6+8n1z6ubOPDuQuIuh4EpQx6nupzTUqv7uRa4Ti29MrzzSf+ElJ5u3KgplQQ0Qzbo4JTGrsE2PqfMLHnjv00S9BKVpZeDyr0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787322160; c=relaxed/simple; bh=5sF0RXwyr0iMr8MjaOHL35Z1gq2gMeitEA/FYdpqM4E=; h=Message-ID:Date:From:To:Cc:Subject:MIME-Version:Content-Type: Content-Disposition; b=p78V4+y41TE3pw7+DgT3Llkb0GsizLdJKiSFn+0fgQ+7UfAJPZ6wfM8aQrgwTiN4zinU9QwkufRS4KtS4EQRo4flydLD34n4k9S8urzlBrRbivsHPBIJgR9lqI/gJbME3m7aZitXZ2iEFSYJljHvZQya7tFqPgeNijRdiHTmFv4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=eqd2RxcE; arc=none smtp.client-ip=209.85.216.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="eqd2RxcE" Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-381c51fde6bso1112889a91.2 for ; Fri, 21 Aug 2026 07:22:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787322159; x=1787926959; darn=vger.kernel.org; h=content-disposition:content-type:mime-version:subject:cc:to:from :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=cYgPMvXM9do2k+pBY2KeyKNzXmSFLJSbdwBoL623krU=; b=eqd2RxcE6Q04O0xKq8dqpY4x9lPeZjTQ733sjIEp2d0zYJifla1G+Msh4qtRi7YwKs Dya/ChYAo/nWRPlahWo3Al+EfrOJIvkWlEUU93L4AL0XHdvGh/RLgobg61IXn3+yaqaG w2A3QBYPpM5iADkmsu3bQVN3719WSFxdS8JaMUJ8A6x4IJN7HasbDS1LtYoyuXdBSTf8 ub5UmuvG2in/PzwB4zEz6OKfSOQR8zIqGXQd6wvIrf7lnDvUe3nbZwsT9hG62vXS5NJv 0ROExDDkiruqQr+rG1BuDaTfnGnXlYzUTC3opSyaT+DS4wtYmtJBoF9JrwgUPCnOHYR5 3uBg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787322159; x=1787926959; h=content-disposition:content-type:mime-version:subject:cc:to:from :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=cYgPMvXM9do2k+pBY2KeyKNzXmSFLJSbdwBoL623krU=; b=s26Yrrmp3KqN+Xflyd/TLYFAvvqgIC8BlqGZUdGApnkbs2bBdcqNUuBwJyeVv9lLq5 Tui34muGVAXdQsS9q0ViUx8CG0E2WP7k/TrB4dJMzvdbRx2lIdgrY4nPRLm1BV0bhYa2 U+5uDjwu1m6y2RgIyoVq0PtaLGXCgB4IPuETASLvu0s87X8P5VgMwGlb8UWn4eEY/GV/ Q5kl59D/fG0Wnv910uVcI2OZAYXdiiT9Pklu3BqXLQ4MF3tHVVVw8MSd4w6X2kYms5+b M+hd+/v8LUq7m6lzKqbB/QQ5bRRuXuerYY2205e+8BuE6CbAm8IpU1jGW2xaifAkbNOU DvwA== X-Forwarded-Encrypted: i=1; AHgh+RoNVJ1ZkBmlVEoIAKA6G/vU/w1yXAWmP2EkvzF4/saveG57VuL3E+BDPh7ztdWASwKQ7PxqFZcsUgJu1MA=@vger.kernel.org X-Gm-Message-State: AFuF++kTkjaegaoDzE3DjuQJFakHx1VbpNRFQHjFTIassMoE2SMLxEFZ ULGozwgWI7w6KycRkmiPJkiRxnXQbV3fx9OX6rB7hPg8LlD422we513AA0Knl1wEoik= X-Gm-Gg: AR+sD13HU9qZkyISzJINlCnXmtutgbCXGu4XTSG2vBLf3rUOHhsZchaPaCMgmlJDp9L HWuZee9PgkqJ7s3QRn0ERtqhsJ/qU3vaba6QizxwV2erSTnVgcbOuXuwowOPCeZACjjgd9VqYVd 3ihISI5KIgg9+GXYxtqg6HVheyWN+kEpApJg5z+Iay7huJ1onyJd0WKfyhH6V3lyyIkD1sueF+S FR/rc45UoPS3eqdf4eLnkoeVolPXGah+FCyMR9ui83OnPHgogSqnI7P9smr/Sg3B+JWW1hVuoZj 5udDHBluJotQM410tdMWQ8Fw6lWKMSYhVBynh0JkOS6BHW4mZa2EPKOJvn42ygsAyaW1ylJlYnt sePR53o7TVCsHbJps7WZGbMcRXf++JKjTH0sq0wIraV01PCvcaNquTh396NP4RZFbGCqngp4+FJ 9uDz8m0joKnmdpfAB9yD9UdD8aBzbsgDTKXnTFDY2smAiNs7diMDtcFsh0B1m89VRa3QVO1DYEX 7gT8trlQtpIEYhwM56lWF9ZMuDd1opJW//R/qIRz59Fvg== X-Received: by 2002:a17:90b:3bc7:b0:395:4de4:92c8 with SMTP id 98e67ed59e1d1-395c386e405mr12977823a91.15.1787322158529; Fri, 21 Aug 2026 07:22:38 -0700 (PDT) Received: from localhost (75-172-9-230.tukw.qwest.net. [75.172.9.230]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-327bf10b584sm44718958eec.16.2026.08.21.07.22.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 21 Aug 2026 07:22:37 -0700 (PDT) Message-ID: <6a885f2d.d76d81af.1755f0.2cd9@mx.google.com> X-Google-Original-Message-ID: Date: Fri, 21 Aug 2026 07:22:29 -0700 From: Dennis Tighe To: Namjae Jeon , Hyunchul Lee Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH] ntfs: reject zero sectors_per_cluster in the boot sector Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" is_boot_sector_ntfs() checks the boot sector's sectors_per_cluster field with a range test that rejects 0x81..0xf3 but accepts 0. A zero value then reaches parse_ntfs_boot_sector(): sectors_per_cluster_bits =3D ffs(sectors_per_cluster) - 1; ... vol->cluster_size =3D vol->sector_size << sectors_per_cluster_bits; ffs(0) is 0, so sectors_per_cluster_bits becomes (unsigned)-1 and the shift is undefined: UBSAN: shift-out-of-bounds in fs/ntfs/super.c:673:39 shift exponent 4294967295 is too large for 32-bit type 'int' Reject sectors_per_cluster =3D=3D 0 alongside the existing range check. Fixes: 6251f0b0de7d ("ntfs: update super block operations") Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Dennis Tighe --- is_boot_sector_ntfs() is where the driver decides an image is NTFS, so rejecting sectors_per_cluster =3D=3D 0 there stops the bad geometry before parse_ntfs_boot_sector() computes ffs(0) - 1. Reached by mounting a test image on my dev machine. A reproducer is available on request. fs/ntfs/super.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/fs/ntfs/super.c b/fs/ntfs/super.c index d400fea32..48bea5ce1 100644 --- a/fs/ntfs/super.c +++ b/fs/ntfs/super.c @@ -557,8 +557,9 @@ static bool is_boot_sector_ntfs(const struct super_bloc= k *sb, * Check sectors per cluster value is valid and the cluster size * is not above the maximum (2MB). */ - if (b->bpb.sectors_per_cluster > 0x80 && - b->bpb.sectors_per_cluster < 0xf4) + if (!b->bpb.sectors_per_cluster || + (b->bpb.sectors_per_cluster > 0x80 && + b->bpb.sectors_per_cluster < 0xf4)) goto not_ntfs; =20 /* Check reserved/unused fields are really zero. */