Fix possible UDF deadlock and memory corruption (CVE-2006-4145)

UDF code is not really ready to handle extents larger that 1GB. This is
the easy way to forbid creating those.

Also truncation code did not count with the case when there are no
extents in the file and we are extending the file.

Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
This commit is contained in:
Jan Kara 2006-08-15 13:56:26 +02:00 коммит произвёл Greg Kroah-Hartman
Родитель c164a9ba0a
Коммит 00a2b0f6dd
2 изменённых файлов: 43 добавлений и 29 удалений

Просмотреть файл

@ -1659,7 +1659,7 @@ static int udf_fill_super(struct super_block *sb, void *options, int silent)
iput(inode);
goto error_out;
}
sb->s_maxbytes = MAX_LFS_FILESIZE;
sb->s_maxbytes = 1<<30;
return 0;
error_out:

Просмотреть файл

@ -239,6 +239,19 @@ void udf_truncate_extents(struct inode * inode)
{
if (offset)
{
/*
* OK, there is not extent covering inode->i_size and
* no extent above inode->i_size => truncate is
* extending the file by 'offset'.
*/
if ((!bh && extoffset == udf_file_entry_alloc_offset(inode)) ||
(bh && extoffset == sizeof(struct allocExtDesc))) {
/* File has no extents at all! */
memset(&eloc, 0x00, sizeof(kernel_lb_addr));
elen = EXT_NOT_RECORDED_NOT_ALLOCATED | offset;
udf_add_aext(inode, &bloc, &extoffset, eloc, elen, &bh, 1);
}
else {
extoffset -= adsize;
etype = udf_next_aext(inode, &bloc, &extoffset, &eloc, &elen, &bh, 1);
if (etype == (EXT_NOT_RECORDED_NOT_ALLOCATED >> 30))
@ -273,6 +286,7 @@ void udf_truncate_extents(struct inode * inode)
}
}
}
}
UDF_I_LENEXTENTS(inode) = inode->i_size;
udf_release_data(bh);