From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 296D13DEFE7; Tue, 21 Jul 2026 22:38:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784673487; cv=none; b=PzogH8hKy2Lq1C1GnmoNNTBK4zhZUDCjMm40dU/wCwp43YuKpPprr3Q0e+2UQ18E/KIM/G9qA+ecfGA+2WSripdgya4bLm4EJpltnyi06R8G8Bk0COtirsR1xx4uzzqYjOsUEYsX0AuYZgp/ul+ZkEuJXgMmLKFhGuKvIwP3oQA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784673487; c=relaxed/simple; bh=k8oek4B6ibAEVcmAJfr2k+SLGcRlOeWISUlxhgahhj4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=V8iEWDHvnAT7SgV4jJz8nWzBgOIkuC+zdko99soG+py50fpX3LhsUVE+nlj64UhNnYIeJYSLR5EAEiVijtd80wmtFlQ6dtNiyQigkOduXyD9FDnsUAzKm5yIOBlWSGr5pfsP6RQvM7I5xcQmLghNurRH0NvXCl0TRUqcxktB42s= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=PFi4XvbA; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="PFi4XvbA" Received: by smtp.kernel.org (Postfix) with ESMTPSA id F29201F00A3A; Tue, 21 Jul 2026 22:38:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1784673481; bh=vWWgcg9+QcPFoEk1KNpwc0k0di/FWgNZ9TlB0IdDayw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=PFi4XvbAufcvArYGvhuuDCoJFA0FOg9TCTbE3g+hQTzh3hoamL3AkSTRsr7tkbK7r vccDGDOUuNl+XQb3jW6EPvpq29i7ZgAG1h8Fu2yyDIpwr8r4MlbLHVYcHKO8Bwvk8F Rwah1+0OoAabwTrTtMWsjZNYYWk7Mwl1SKCsTrKg= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Michael Bommarito , Bryam Vargas , Jan Kara Subject: [PATCH 5.10 126/699] isofs: bound Rock Ridge symlink components to the SL record Date: Tue, 21 Jul 2026 17:18:05 +0200 Message-ID: <20260721152358.548829943@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260721152355.667394603@linuxfoundation.org> References: <20260721152355.667394603@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 5.10-stable review patch. If anyone has any objections, please let me know. ------------------ From: Bryam Vargas commit 5fa1d6a5ec2356d2107dead614437c66fa7138b1 upstream. get_symlink_chunk() and the SL handling in parse_rock_ridge_inode_internal() walk the variable-length components of a Rock Ridge "SL" (symbolic link) record. Each component is a two-byte header (flags, len) followed by len bytes of text, so it occupies slp->len + 2 bytes. Both loops read slp->len and advance to the next component, and get_symlink_chunk() additionally does memcpy(rpnt, slp->text, slp->len), but neither checks that the component lies within the SL record before dereferencing it. A crafted SL record whose component declares a len that runs past the record (rr->len) therefore triggers an out-of-bounds read of up to 255 bytes. When the record sits at the tail of its backing buffer - for example a small kmalloc()ed continuation block reached through a CE record - the read crosses the allocation; get_symlink_chunk() then copies the out-of-bounds bytes into the symlink body returned to user space by readlink(), disclosing adjacent kernel memory. ISO 9660 images are routinely mounted from untrusted removable media - desktop environments auto-mount them (e.g. via udisks2) without CAP_SYS_ADMIN - so the record contents are attacker-controlled. Reject any component that does not fit in the remaining record bytes before using it. In get_symlink_chunk() return NULL, like the existing output-buffer (plimit) checks, so a malformed record makes readlink() fail with -EIO rather than silently returning a truncated target; in parse_rock_ridge_inode_internal() stop the inode-size walk. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Cc: stable@vger.kernel.org Suggested-by: Michael Bommarito Signed-off-by: Bryam Vargas Link: https://patch.msgid.link/20260607011823.217748-1-hexlabsecurity@proton.me Signed-off-by: Jan Kara Signed-off-by: Greg Kroah-Hartman --- fs/isofs/rock.c | 11 +++++++++++ 1 file changed, 11 insertions(+) --- a/fs/isofs/rock.c +++ b/fs/isofs/rock.c @@ -464,6 +464,9 @@ repeat: inode->i_size = symlink_len; while (slen > 1) { rootflag = 0; + /* keep the component within the SL record */ + if (slp->len + 2 > slen) + goto eio; switch (slp->flags & ~1) { case 0: inode->i_size += @@ -619,6 +622,14 @@ static char *get_symlink_chunk(char *rpn slp = &rr->u.SL.link; while (slen > 1) { rootflag = 0; + /* + * A component is slp->len + 2 bytes (a two-byte header plus + * len bytes of text). If it does not fit in the bytes left in + * the SL record the record is malformed: fail like the plimit + * checks below so readlink() returns -EIO, not a truncated path. + */ + if (slp->len + 2 > slen) + return NULL; switch (slp->flags & ~1) { case 0: if (slp->len > plimit - rpnt)