6.5-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pavel Skripkin paskripkin@gmail.com
commit 34e6552a442f268eefd408e47f4f2d471aa64829 upstream.
Syzbot was able to create a device which has the last sector of size 512.
After failing to boot from initial sector, reading from boot info from offset 511 causes OOB read.
To prevent such reports add sanity check to validate if size of buffer_head if big enough to hold ntfs3 bootinfo
Fixes: 6a4cd3ea7d77 ("fs/ntfs3: Alternative boot if primary boot is corrupted") Reported-by: syzbot+53ce40c8c0322c06aea5@syzkaller.appspotmail.com Signed-off-by: Pavel Skripkin paskripkin@gmail.com Signed-off-by: Konstantin Komarov almaz.alexandrovich@paragon-software.com Signed-off-by: Greg Kroah-Hartman gregkh@linuxfoundation.org --- fs/ntfs3/super.c | 5 +++++ 1 file changed, 5 insertions(+)
--- a/fs/ntfs3/super.c +++ b/fs/ntfs3/super.c @@ -855,6 +855,11 @@ static int ntfs_init_from_boot(struct su
check_boot: err = -EINVAL; + + /* Corrupted image; do not read OOB */ + if (bh->b_size - sizeof(*boot) < boot_off) + goto out; + boot = (struct NTFS_BOOT *)Add2Ptr(bh->b_data, boot_off);
if (memcmp(boot->system_id, "NTFS ", sizeof("NTFS ") - 1)) {