From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.linuxfoundation.org ([140.211.169.12]:45692 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727434AbeJBSjb (ORCPT ); Tue, 2 Oct 2018 14:39:31 -0400 Date: Tue, 2 Oct 2018 04:56:31 -0700 From: Greg Kroah-Hartman To: Guenter Roeck Cc: Zubin Mithra , stable@vger.kernel.org, Theodore Ts'o , stable@kernel.org Subject: Re: [PATCH v4.9.y] ext4: never move the system.data xattr out of the inode body Message-ID: <20181002115631.GC3030@kroah.com> References: <1538327868-27369-1-git-send-email-linux@roeck-us.net> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1538327868-27369-1-git-send-email-linux@roeck-us.net> Sender: stable-owner@vger.kernel.org List-ID: On Sun, Sep 30, 2018 at 10:17:48AM -0700, Guenter Roeck wrote: > From: Theodore Ts'o > > commit 8cdb5240ec5928b20490a2bb34cb87e9a5f40226 upstream. > > When expanding the extra isize space, we must never move the > system.data xattr out of the inode body. For performance reasons, it > doesn't make any sense, and the inline data implementation assumes > that system.data xattr is never in the external xattr block. > > This addresses CVE-2018-10880 > > https://bugzilla.kernel.org/show_bug.cgi?id=200005 > > Signed-off-by: Theodore Ts'o > Cc: stable@kernel.org > [groeck: Context changes] > Signed-off-by: Guenter Roeck > --- > I thought the 4.4.y backport should apply, but I think it doesn't after > all. This backport applies to v4.9.y. Thanks, that worked. greg k-h