ntfs: reject invalid sectors_per_cluster in the boot sector

is_boot_sector_ntfs() checks the boot sector's sectors_per_cluster field
with a range test that rejects 0x81..0xf3 but accepts 0 and other
non-power-of-two counts. A zero value reaches parse_ntfs_boot_sector():

	sectors_per_cluster_bits = ffs(sectors_per_cluster) - 1;
	...
	vol->cluster_size = vol->sector_size << sectors_per_cluster_bits;

ffs(0) is 0, so sectors_per_cluster_bits becomes (unsigned)-1 and the
shift is undefined:

  UBSAN: shift-out-of-bounds in fs/ntfs/super.c:673:39
  shift exponent 4294967295 is too large for 32-bit type 'int'

This change rejects any non-power-of-two value, since it feeds the
aforementioned shift via ffs() - 1, which only yields the correct shift for a
power of two.

Fixes: 6251f0b0de ("ntfs: update super block operations")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Dennis Tighe <dennis.tighe@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
This commit is contained in:
Dennis Tighe 2026-08-25 22:09:34 -07:00 committed by Namjae Jeon
parent c8504fc124
commit 323751a604

View File

@ -557,8 +557,8 @@ static bool is_boot_sector_ntfs(const struct super_block *sb,
* Check sectors per cluster value is valid and the cluster size
* is not above the maximum (2MB).
*/
if (b->bpb.sectors_per_cluster > 0x80 &&
b->bpb.sectors_per_cluster < 0xf4)
if (b->bpb.sectors_per_cluster < 0xf4 &&
!is_power_of_2(b->bpb.sectors_per_cluster))
goto not_ntfs;
/* Check reserved/unused fields are really zero. */