Skip to content

udf: validate vat20->lengthHeader and VAT inode size in udf_load_vat() - #2623

Closed
vfsci-bot[bot] wants to merge 1 commit into
vfs.base.cifrom
pw/1169469/vfs.base.ci
Closed

vfsci-bot[bot] wants to merge 1 commit into
vfs.base.cifrom
pw/1169469/vfs.base.ci

Conversation

@vfsci-bot

@vfsci-bot vfsci-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown

Series: https://patchwork.kernel.org/project/linux-fsdevel/list/?series=1169469
Submitter: Hui Peng
Version: 1
Patches: 1/1
Message-ID: <20260919222600.3793513-1-benquike@gmail.com>
Base: vfs.base.ci
Lore: https://lore.kernel.org/linux-fsdevel/20260919222600.3793513-1-benquike@gmail.com


Automated by ml2pr

In udf_load_vat() (fs/udf/super.c), validate that vat20->lengthHeader is
at least sizeof(struct virtualAllocationTable20) and does not exceed the
mapped buffer or VAT inode size so computing the VAT table pointer and
entry count cannot underflow or read out of bounds.

Fixes: 1da177e ("Linux-2.6.12-rc2")
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
@vfsci-bot

vfsci-bot Bot commented Oct 4, 2026

Copy link
Copy Markdown
Author

This PR is older than 14 days. Closing automatically. If the series is still relevant, a new version will create a new PR.


Automated by ml2pr

@vfsci-bot vfsci-bot Bot closed this Oct 4, 2026
@vfsci-bot
vfsci-bot Bot deleted the pw/1169469/vfs.base.ci branch October 4, 2026 05:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant