* [PATCH] ext4: fix OOB memmove in ext4_xattr_set_entry
@ 2026-09-18 10:12 Zhao Gongyi
2026-09-18 10:34 ` sashiko-bot
0 siblings, 1 reply; 2+ messages in thread
From: Zhao Gongyi @ 2026-09-18 10:12 UTC (permalink / raw)
To: Theodore Ts'o
Cc: Andreas Dilger, Baokun Li, Jan Kara, Ojaswin Mujoo,
Ritesh Harjani (IBM), Zhang Yi, linux-ext4, linux-kernel, stable,
Zhao Gongyi
A corrupted filesystem can leave an inode marked as having inline data
while the system.data xattr is missing. ext4_destroy_inline_data_nolock()
then asks ext4_xattr_set_entry() to remove an entry even though
ext4_xattr_ibody_find() left the search state at the insertion position.
In the syzkaller reproducer, the old xattr value offset is smaller than
min_offs. ext4_xattr_set_entry() then computes val - first_val for
memmove(), the length wraps to a huge size_t, and memmove() can run out of
the xattr buffer. This results in an out-of-bounds memmove and a kernel
page fault.
A crafted corrupted ext4 image can trigger this while inline data is being
converted out of the inode. Treat the inconsistent inline/xattr state as
filesystem corruption before updating the xattr entry.
The issue was found by syzkaller and reproduced with the generated C
reproducer. The crash signature is:
BUG: unable to handle page fault for address: ffff8880074cf000
RIP: 0010:memmove+0x28/0x1b0
Call Trace:
ext4_xattr_set_entry+0xe2f/0x1e90 fs/ext4/xattr.c:1761
ext4_xattr_ibody_set+0x3d6/0x5d0 fs/ext4/xattr.c:2268
ext4_destroy_inline_data_nolock+0x288/0x5b0 fs/ext4/inline.c:467
ext4_convert_inline_data_nolock+0x178/0xe80 fs/ext4/inline.c:1222
ext4_convert_inline_data+0x52a/0x610 fs/ext4/inline.c:2083
ext4_fallocate+0x1a0/0x3ba0 fs/ext4/extents.c:4752
Reject the missing system.data xattr before destroying inline data, and
validate the old value offset before ext4_xattr_set_entry() reaches the
memmove().
The crash was reproduced on unpatched 7.3.0-rc3 and 6.6.122 kernels. With
this fix applied to both versions, the same syzkaller C reproducer ran for
120 seconds without triggering KASAN, Oops, a memmove fault, or panic.
Fixes: 67cf5b09a46f ("ext4: add the basic function for inline data support")
Cc: stable@vger.kernel.org # v3.8+
Signed-off-by: Zhao Gongyi <zhaogongyi@bytedance.com>
---
fs/ext4/inline.c | 6 ++++++
fs/ext4/xattr.c | 12 ++++++++++++
2 files changed, 18 insertions(+)
diff --git a/fs/ext4/inline.c b/fs/ext4/inline.c
index ceee69a66..0a30d40cb 100644
--- a/fs/ext4/inline.c
+++ b/fs/ext4/inline.c
@@ -461,6 +461,12 @@ static int ext4_destroy_inline_data_nolock(handle_t *handle,
error = ext4_xattr_ibody_find(inode, &i, &is);
if (error)
goto out;
+ if (is.s.not_found) {
+ EXT4_ERROR_INODE(inode,
+ "corrupted inline data without system.data xattr");
+ error = -EFSCORRUPTED;
+ goto out;
+ }
BUFFER_TRACE(is.iloc.bh, "get_write_access");
error = ext4_journal_get_write_access(handle, inode->i_sb, is.iloc.bh,
diff --git a/fs/ext4/xattr.c b/fs/ext4/xattr.c
index 5c310747b..9a0ee5779 100644
--- a/fs/ext4/xattr.c
+++ b/fs/ext4/xattr.c
@@ -1712,6 +1712,18 @@ static int ext4_xattr_set_entry(struct ext4_xattr_info *i,
}
}
+ if (!s->not_found && here->e_value_size && !here->e_value_inum) {
+ size_t offs = le16_to_cpu(here->e_value_offs);
+
+ if (offs < min_offs) {
+ EXT4_ERROR_INODE(inode,
+ "corrupted xattr: value offset %zu < min_offs %zu",
+ offs, min_offs);
+ ret = -EFSCORRUPTED;
+ goto out;
+ }
+ }
+
/*
* Getting access to old and new ea inodes is subject to failures.
* Finish that work before doing any modifications to the xattr data.
--
2.39.5 (Apple Git-154)
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH] ext4: fix OOB memmove in ext4_xattr_set_entry
2026-09-18 10:12 [PATCH] ext4: fix OOB memmove in ext4_xattr_set_entry Zhao Gongyi
@ 2026-09-18 10:34 ` sashiko-bot
0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-09-18 10:34 UTC (permalink / raw)
To: Zhao Gongyi; +Cc: linux-ext4, tytso
> A corrupted filesystem can leave an inode marked as having inline data
> while the system.data xattr is missing. ext4_destroy_inline_data_nolock()
> then asks ext4_xattr_set_entry() to remove an entry even though
> ext4_xattr_ibody_find() left the search state at the insertion position.
>
> In the syzkaller reproducer, the old xattr value offset is smaller than
> min_offs. ext4_xattr_set_entry() then computes val - first_val for
> memmove(), the length wraps to a huge size_t, and memmove() can run out of
> the xattr buffer. This results in an out-of-bounds memmove and a kernel
> page fault.
>
> A crafted corrupted ext4 image can trigger this while inline data is being
> converted out of the inode. Treat the inconsistent inline/xattr state as
> filesystem corruption before updating the xattr entry.
>
> [ ... ]
> 120 seconds without triggering KASAN, Oops, a memmove fault, or panic.
>
> Fixes: 67cf5b09a46f ("ext4: add the basic function for inline data support")
> Cc: stable@vger.kernel.org # v3.8+
> Signed-off-by: Zhao Gongyi <zhaogongyi@bytedance.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260918101249.43643-1-zhaogongyi@bytedance.com?part=1
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-18 10:34 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-18 10:12 [PATCH] ext4: fix OOB memmove in ext4_xattr_set_entry Zhao Gongyi
2026-09-18 10:34 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox