fs/ntfs3: Fix OOB read in ntfs_init_from_boot
authorPavel Skripkin <paskripkin@gmail.com>
Thu, 13 Jul 2023 19:41:46 +0000 (22:41 +0300)
committerKonstantin Komarov <almaz.alexandrovich@paragon-software.com>
Thu, 28 Sep 2023 12:04:05 +0000 (15:04 +0300)
commit34e6552a442f268eefd408e47f4f2d471aa64829
tree52f713ca4d6e787f362dc661af08e572bc4af188
parent8e7e27b2ee1e19c4040d4987e345f678a74c0aed
fs/ntfs3: Fix OOB read in ntfs_init_from_boot

Syzbot was able to create a device which has the last sector of size
512.

After failing to boot from initial sector, reading from boot info from
offset 511 causes OOB read.

To prevent such reports add sanity check to validate if size of buffer_head
if big enough to hold ntfs3 bootinfo

Fixes: 6a4cd3ea7d77 ("fs/ntfs3: Alternative boot if primary boot is corrupted")
Reported-by: syzbot+53ce40c8c0322c06aea5@syzkaller.appspotmail.com
Signed-off-by: Pavel Skripkin <paskripkin@gmail.com>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
fs/ntfs3/super.c