mirror of
https://github.com/torvalds/linux.git
synced 2026-09-11 20:13:02 +02:00
ntfs: fix memmove overlap in ntfs_new_attr_flags
When the record shrinks while the payload offsets increase (e.g., enabling
compression reduces padding, making arec_size < old_arec_size, but the header
grows by 8 bytes), moving the name first can overwrite the old mapping_pairs
before they are copied. Move mapping_pairs first in this case.
Since mp_ofs is derived from name_ofs, they always change in the same
direction. Checking name_ofs alone is sufficient.
Fixes: fc053f05ca ("ntfs: add reparse and ea operations")
Cc: stable@vger.kernel.org
Signed-off-by: Hongling Zeng <zenghongling@kylinos.cn>
Reviewed-by: Hyunchul Lee <hyc.lee@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
This commit is contained in:
parent
6faa235a64
commit
acb1095fd2
33
fs/ntfs/ea.c
33
fs/ntfs/ea.c
|
|
@ -753,15 +753,36 @@ static int ntfs_new_attr_flags(struct ntfs_inode *ni, __le32 fattr)
|
|||
old_arec_size = le32_to_cpu(a->length);
|
||||
|
||||
/*
|
||||
* Move payloads before shrinking the record. Otherwise resizing moves
|
||||
* Move payloads before shrinking the record. Otherwise resizing moves
|
||||
* the following attribute over the old payload before it can be copied.
|
||||
*
|
||||
* When offsets increase, move mapping_pairs first to avoid name
|
||||
* overwriting the start of mapping_pairs.
|
||||
*/
|
||||
if (arec_size < old_arec_size) {
|
||||
if (a->name_length && name_ofs != old_name_ofs)
|
||||
memmove((u8 *)a + name_ofs, (u8 *)a + old_name_ofs,
|
||||
a->name_length * sizeof(__le16));
|
||||
if (mp_ofs != old_mp_ofs)
|
||||
memmove((u8 *)a + mp_ofs, (u8 *)a + old_mp_ofs, mp_size);
|
||||
if (name_ofs > old_name_ofs) {
|
||||
/* Payload offsets increased: move mapping pairs first. */
|
||||
if (mp_ofs != old_mp_ofs)
|
||||
memmove((u8 *)a + mp_ofs,
|
||||
(u8 *)a + old_mp_ofs,
|
||||
mp_size);
|
||||
if (a->name_length && name_ofs != old_name_ofs)
|
||||
memmove((u8 *)a + name_ofs,
|
||||
(u8 *)a + old_name_ofs,
|
||||
a->name_length *
|
||||
sizeof(__le16));
|
||||
} else {
|
||||
/* Payload offsets decreased or unchanged: move name first. */
|
||||
if (a->name_length && name_ofs != old_name_ofs)
|
||||
memmove((u8 *)a + name_ofs,
|
||||
(u8 *)a + old_name_ofs,
|
||||
a->name_length *
|
||||
sizeof(__le16));
|
||||
if (mp_ofs != old_mp_ofs)
|
||||
memmove((u8 *)a + mp_ofs,
|
||||
(u8 *)a + old_mp_ofs,
|
||||
mp_size);
|
||||
}
|
||||
}
|
||||
|
||||
err = ntfs_attr_record_resize(ctx->mrec, a, arec_size);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user