mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 01:32:21 +02:00
dm-verity: fix buffer overflow in FEC calculation
There's a buffer overflow in dm-verity-fec:
if (neras && *neras <= v->fec->roots)
fio->erasures[(*neras)++] = i;
This allows *neras to reach roots + 1 (the post-increment pushes it past
roots). This value is then passed as no_eras to decode_rs8(). Inside the
RS decoder (lib/reed_solomon/decode_rs.c:113-121), the erasure locator
polynomial loop writes lambda[j] where j can reach nroots + 1 — one
element past the end of lambda[] (which is sized nroots + 1, valid
indices 0..nroots). The out-of-bounds write lands on syn[0], corrupting
the syndrome buffer.
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Assisted-by: Claude:claude-opus-4-6
Cc: stable@vger.kernel.org
Fixes: a739ff3f54 ("dm verity: add support for forward error correction")
Reviewed-by: Sami Tolvanen <samitolvanen@google.com>
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
This commit is contained in:
parent
a868196f03
commit
31d6e6c0ba
|
|
@ -220,7 +220,7 @@ static int fec_read_bufs(struct dm_verity *v, struct dm_verity_io *io,
|
|||
PTR_ERR(bbuf));
|
||||
|
||||
/* assume the block is corrupted */
|
||||
if (neras && *neras <= v->fec->roots)
|
||||
if (neras && *neras < v->fec->roots)
|
||||
fio->erasures[(*neras)++] = i;
|
||||
|
||||
continue;
|
||||
|
|
@ -238,7 +238,7 @@ static int fec_read_bufs(struct dm_verity *v, struct dm_verity_io *io,
|
|||
* skip if we have already found the theoretical
|
||||
* maximum number (i.e. fec->roots) of erasures
|
||||
*/
|
||||
if (neras && *neras <= v->fec->roots &&
|
||||
if (neras && *neras < v->fec->roots &&
|
||||
fec_is_erasure(v, io, want_digest, bbuf))
|
||||
fio->erasures[(*neras)++] = i;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -47,7 +47,7 @@ struct dm_verity_fec {
|
|||
/* per-bio data */
|
||||
struct dm_verity_fec_io {
|
||||
struct rs_control *rs; /* Reed-Solomon state */
|
||||
int erasures[DM_VERITY_FEC_MAX_ROOTS + 1]; /* erasures for decode_rs8 */
|
||||
int erasures[DM_VERITY_FEC_MAX_ROOTS]; /* erasures for decode_rs8 */
|
||||
u8 *output; /* buffer for corrected output */
|
||||
unsigned int level; /* recursion level */
|
||||
unsigned int nbufs; /* number of buffers allocated */
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user