mirror of
https://github.com/torvalds/linux.git
synced 2026-09-11 20:13:02 +02:00
ntfs: reject invalid sectors_per_cluster in the boot sector
is_boot_sector_ntfs() checks the boot sector's sectors_per_cluster field
with a range test that rejects 0x81..0xf3 but accepts 0 and other
non-power-of-two counts. A zero value reaches parse_ntfs_boot_sector():
sectors_per_cluster_bits = ffs(sectors_per_cluster) - 1;
...
vol->cluster_size = vol->sector_size << sectors_per_cluster_bits;
ffs(0) is 0, so sectors_per_cluster_bits becomes (unsigned)-1 and the
shift is undefined:
UBSAN: shift-out-of-bounds in fs/ntfs/super.c:673:39
shift exponent 4294967295 is too large for 32-bit type 'int'
This change rejects any non-power-of-two value, since it feeds the
aforementioned shift via ffs() - 1, which only yields the correct shift for a
power of two.
Fixes: 6251f0b0de ("ntfs: update super block operations")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Dennis Tighe <dennis.tighe@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
This commit is contained in:
parent
c8504fc124
commit
323751a604
|
|
@ -557,8 +557,8 @@ static bool is_boot_sector_ntfs(const struct super_block *sb,
|
|||
* Check sectors per cluster value is valid and the cluster size
|
||||
* is not above the maximum (2MB).
|
||||
*/
|
||||
if (b->bpb.sectors_per_cluster > 0x80 &&
|
||||
b->bpb.sectors_per_cluster < 0xf4)
|
||||
if (b->bpb.sectors_per_cluster < 0xf4 &&
|
||||
!is_power_of_2(b->bpb.sectors_per_cluster))
|
||||
goto not_ntfs;
|
||||
|
||||
/* Check reserved/unused fields are really zero. */
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user