Skip to content

qnx4: validate xblk_num_xtnts and rootdir size in qnx4_block_map() and mount - #2631

Open
vfsci-bot[bot] wants to merge 1 commit into
vfs.base.cifrom
pw/1169477/vfs.base.ci
Open

vfsci-bot[bot] wants to merge 1 commit into
vfs.base.cifrom
pw/1169477/vfs.base.ci

Conversation

@vfsci-bot

@vfsci-bot vfsci-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown

Series: https://patchwork.kernel.org/project/linux-fsdevel/list/?series=1169477
Submitter: Hui Peng
Version: 1
Patches: 1/1
Message-ID: <20260919222623.3797296-1-benquike@gmail.com>
Base: vfs.base.ci
Lore: https://lore.kernel.org/linux-fsdevel/20260919222623.3797296-1-benquike@gmail.com


Automated by ml2pr

…d mount

In qnx4_block_map() and qnx4_fill_super() (fs/qnx4/inode.c), check that
xblk->xblk_num_xtnts is between 1 and QNX4_MAX_XTNTS_PER_XBLK (60),
return 0 instead of (unsigned long)-EIO on error, and validate the root
directory inode size on mount to prevent out-of-bounds reads past the
512-byte buffer_head.

Fixes: 1da177e ("Linux-2.6.12-rc2")
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant