mirror of
https://github.com/torvalds/linux.git
synced 2026-09-28 03:52:02 +02:00
squashfs: Add dictionary size range check to prevent shift-out-of-bounds
When an abnormal SquashFS image (COMP_OPTS flag is 1 but dictionary size
is 0) is mounted, and performs shift operations using dictionarysize, the
shift exponent is -1, causing a shift-out-of-bounds.
Detail as below:
squashfs_comp_opts(msblk, buffer, length)
squashfs_xz_comp_opts()
if (comp_opts)
n = ffs(opts->dict_size) - 1;<----opts->dict_size=0, n=-1
if (opts->dict_size != (1 << n) && opts->dict_size !=
(1 << n) + (1 << (n + 1))) <----shift-out-of-bounds
Fix it by adding a dictionary size range check before the shift operation.
Fixes: ff750311d3 ("Squashfs: add compression options support to xz decompressor")
Signed-off-by: Ran Hongyun <ranhongyun1@huawei.com>
Link: https://patch.msgid.link/20260713115525.2661734-1-ranhongyun1@huawei.com
Reviewed-by: Phillip Lougher <phillip@squashfs.org.uk>
Reviewed-by: Zhihao Cheng <chengzhihao1@huawei.com>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
This commit is contained in:
parent
1abd643f37
commit
1f7745fb35
|
|
@ -57,10 +57,10 @@ static void *squashfs_xz_comp_opts(struct squashfs_sb_info *msblk,
|
|||
|
||||
opts->dict_size = le32_to_cpu(comp_opts->dictionary_size);
|
||||
|
||||
/* the dictionary size should be 2^n or 2^n+2^(n+1) */
|
||||
/* the dictionary size should be positive and 2^n or 2^n+2^(n+1) */
|
||||
n = ffs(opts->dict_size) - 1;
|
||||
if (opts->dict_size != (1 << n) && opts->dict_size != (1 << n) +
|
||||
(1 << (n + 1))) {
|
||||
if (opts->dict_size <= 0 || (opts->dict_size != (1 << n) &&
|
||||
opts->dict_size != (1 << n) + (1 << (n + 1)))) {
|
||||
err = -EIO;
|
||||
goto out;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user