From: Tabriz Hasanli <cybersec467@gmail.com>
To: linux-kernel@vger.kernel.org, ntfs3@lists.linux.dev
Cc: almaz.alexandrovich@paragon-software.com, w@1wt.eu,
Tabriz Hasanli <cybersec467@gmail.com>
Subject: [PATCH 0/1] fs/ntfs3: fix OOB writes in do_action() log replay via unvalidated trailing index entry
Date: Mon, 31 Aug 2026 10:23:43 -0400 [thread overview]
Message-ID: <20260831142344.472594-1-cybersec467@gmail.com> (raw)
Hi Willy, Konstantin,
Thank you for the quick and detailed feedback.
First, apologies about the display name — it was a placeholder from
when I first created the account. I have since updated it to my real
name: Tabriz Hasanli.
As requested, here is the fix as a proper git format-patch against
mainline (cf72cbb39). A single patch addresses both check_if_alloc_index()
and check_if_root_index() since they share the same root cause and
the same fix pattern.
Per your note that crafted-FS issues are outside the private
disclosure threat model, I am sending this to the public lists.
Summary of the bug:
check_if_alloc_index() and check_if_root_index() do not stop at
de_is_last() and do not validate the target entry at attr_off.
This allows a crafted NTFS image's $LogFile to direct four
do_action() write operations to an attacker-controlled fake entry
in the trailing gap, producing heap OOB writes of 8 or 56 bytes
during mount.
These are variant siblings of the view.data_off fix (3e127829e57f)
and the DeleteIndexEntryAllocation fix (fc4626bb3656).
Confirmed with userspace ASan harnesses using kernel-faithful
512-byte INDEX_BUFFER geometry (fix_off=0x28, fix_num=2, full
check_index_buffer gate chain). Harness source files are
available on request.
Thanks,
Tabriz
Tabriz Hasanli (1):
fs/ntfs3: validate target index entry in
check_if_alloc_index/check_if_root_index
fs/ntfs3/fslog.c | 42 ++++++++++++++++++++++++++++++++++++------
1 file changed, 36 insertions(+), 6 deletions(-)
--
2.53.0
next reply other threads:[~2026-08-31 14:24 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 14:23 Tabriz Hasanli [this message]
2026-08-31 14:23 ` [PATCH 1/1] fs/ntfs3: validate target index entry in check_if_alloc_index/check_if_root_index Tabriz Hasanli
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831142344.472594-1-cybersec467@gmail.com \
--to=cybersec467@gmail.com \
--cc=almaz.alexandrovich@paragon-software.com \
--cc=linux-kernel@vger.kernel.org \
--cc=ntfs3@lists.linux.dev \
--cc=w@1wt.eu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.