mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
mtd: mtdpart: validate partition bounds in mtd_add_partition()
mtd_add_partition() checks that 'length' is positive but does not
validate that 'offset + length' fits within the parent partition's
size. A userspace caller using the BLKPG_ADD_PARTITION ioctl can
supply a crafted large 'length' value that passes the length <= 0
check, causing add_mtd_device() to fire a WARN_ON() when it detects
the oversized partition.
Fix this by adding explicit bounds checks before allocate_partition()
is called:
- Reject negative or out-of-range offsets.
- Use u64 arithmetic to safely check offset + length <= parent_size,
avoiding potential signed integer overflow.
Reported-by: syzbot+3ae80219c633aca5431c@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=3ae80219c633aca5431c
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
This commit is contained in:
parent
ae9d8058f1
commit
a74e31d0a2
|
|
@ -267,6 +267,11 @@ int mtd_add_partition(struct mtd_info *parent, const char *name,
|
|||
if (length <= 0)
|
||||
return -EINVAL;
|
||||
|
||||
if (offset < 0 || offset >= (long long)parent_size)
|
||||
return -EINVAL;
|
||||
|
||||
if ((u64)offset + (u64)length > parent_size)
|
||||
return -EINVAL;
|
||||
memset(&part, 0, sizeof(part));
|
||||
part.name = name;
|
||||
part.size = length;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user