ntfs: fix memmove overlap in ntfs_new_attr_flags

When the record shrinks while the payload offsets increase (e.g., enabling
compression reduces padding, making arec_size < old_arec_size, but the header
grows by 8 bytes), moving the name first can overwrite the old mapping_pairs
before they are copied. Move mapping_pairs first in this case.

Since mp_ofs is derived from name_ofs, they always change in the same
direction. Checking name_ofs alone is sufficient.

Fixes: fc053f05ca ("ntfs: add reparse and ea operations")
Cc: stable@vger.kernel.org
Signed-off-by: Hongling Zeng <zenghongling@kylinos.cn>
Reviewed-by: Hyunchul Lee <hyc.lee@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
This commit is contained in:
Hongling Zeng 2026-08-24 15:59:35 +08:00 committed by Namjae Jeon
parent 6faa235a64
commit acb1095fd2

View File

@ -753,15 +753,36 @@ static int ntfs_new_attr_flags(struct ntfs_inode *ni, __le32 fattr)
old_arec_size = le32_to_cpu(a->length);
/*
* Move payloads before shrinking the record. Otherwise resizing moves
* Move payloads before shrinking the record. Otherwise resizing moves
* the following attribute over the old payload before it can be copied.
*
* When offsets increase, move mapping_pairs first to avoid name
* overwriting the start of mapping_pairs.
*/
if (arec_size < old_arec_size) {
if (a->name_length && name_ofs != old_name_ofs)
memmove((u8 *)a + name_ofs, (u8 *)a + old_name_ofs,
a->name_length * sizeof(__le16));
if (mp_ofs != old_mp_ofs)
memmove((u8 *)a + mp_ofs, (u8 *)a + old_mp_ofs, mp_size);
if (name_ofs > old_name_ofs) {
/* Payload offsets increased: move mapping pairs first. */
if (mp_ofs != old_mp_ofs)
memmove((u8 *)a + mp_ofs,
(u8 *)a + old_mp_ofs,
mp_size);
if (a->name_length && name_ofs != old_name_ofs)
memmove((u8 *)a + name_ofs,
(u8 *)a + old_name_ofs,
a->name_length *
sizeof(__le16));
} else {
/* Payload offsets decreased or unchanged: move name first. */
if (a->name_length && name_ofs != old_name_ofs)
memmove((u8 *)a + name_ofs,
(u8 *)a + old_name_ofs,
a->name_length *
sizeof(__le16));
if (mp_ofs != old_mp_ofs)
memmove((u8 *)a + mp_ofs,
(u8 *)a + old_mp_ofs,
mp_size);
}
}
err = ntfs_attr_record_resize(ctx->mrec, a, arec_size);