f2fs: validate dentry name length before lookup compares it

The f2fs dentry lookup path can use the on-disk name length before
checking that the name fits in the dentry filename area.  A corrupted
dentry can then make lookup read beyond the filename slots.

The bounds check needs to happen before any comparison that consumes
the name length from disk.

Reject dentries with invalid name lengths before comparing their names.

Assisted-by: Codex:gpt-5.5-cyber-preview
Signed-off-by: Samuel Moelius <sam.moelius@trailofbits.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
This commit is contained in:
Samuel Moelius
2026-06-03 16:11:26 +00:00
committed by Jaegeuk Kim
parent cfcd0e49a1
commit 90e02a8e1b

View File

@@ -250,6 +250,11 @@ struct f2fs_dir_entry *f2fs_find_target_dentry(const struct f2fs_dentry_ptr *d,
continue;
}
if (unlikely(le16_to_cpu(de->name_len) > F2FS_NAME_LEN ||
bit_pos + GET_DENTRY_SLOTS(le16_to_cpu(de->name_len)) >
d->max))
return ERR_PTR(-EFSCORRUPTED);
if (!use_hash || de->hash_code == fname->hash) {
res = f2fs_match_name(d->inode, fname,
d->filename[bit_pos],