udf: Limit sparing table size
authorJan Kara <jack@suse.cz>
Fri, 25 Sep 2020 12:53:08 +0000 (14:53 +0200)
committerJan Kara <jack@suse.cz>
Tue, 29 Sep 2020 15:21:54 +0000 (17:21 +0200)
Although UDF standard allows it, we don't support sparing table larger
than a single block. Check it during mount so that we don't try to
access memory beyond end of buffer.

Reported-by: syzbot+9991561e714f597095da@syzkaller.appspotmail.com
Signed-off-by: Jan Kara <jack@suse.cz>
fs/udf/super.c

index 413a50599d1c45a7bb48ece10ee0fd44f39ad3c9..faf2017ada1114ff78207e2401456dd2c0cbe6b3 100644 (file)
@@ -1345,6 +1345,12 @@ static int udf_load_sparable_map(struct super_block *sb,
                        (int)spm->numSparingTables);
                return -EIO;
        }
+       if (le32_to_cpu(spm->sizeSparingTable) > sb->s_blocksize) {
+               udf_err(sb, "error loading logical volume descriptor: "
+                       "Too big sparing table size (%u)\n",
+                       le32_to_cpu(spm->sizeSparingTable));
+               return -EIO;
+       }
 
        for (i = 0; i < spm->numSparingTables; i++) {
                loc = le32_to_cpu(spm->locSparingTable[i]);