mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-30 13:23:02 -04:00
udf: Fix i_lenExtents truncation on 32-bit kernels
In udf_do_extend_file() the total extent length is rounded up to a block
boundary with:
iinfo->i_lenExtents = (iinfo->i_lenExtents + sb->s_blocksize - 1) &
~(sb->s_blocksize - 1);
i_lenExtents is a __u64, but sb->s_blocksize is unsigned long. On 32-bit
kernels unsigned long is 32-bit, so ~(sb->s_blocksize - 1) is a 32-bit
value (e.g. 0xfffff800 for a 2 KiB block) that is zero-extended in the AND,
clearing the upper 32 bits of i_lenExtents. For UDF files whose total
extent length exceeds 4 GiB this truncates i_lenExtents when the file is
extended, corrupting the tracked extent length.
Cast the block size to 64-bit before forming the mask. 64-bit kernels are
unaffected.
Fixes: 48d6d8ff7d ("udf: cache struct udf_inode_info")
Cc: stable@vger.kernel.org
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
Link: https://patch.msgid.link/20260722082425.213311-1-zhanxusheng@xiaomi.com
Signed-off-by: Jan Kara <jack@suse.cz>
This commit is contained in:
@@ -531,7 +531,7 @@ static int udf_do_extend_file(struct inode *inode,
|
||||
sb->s_blocksize - 1) & ~(sb->s_blocksize - 1));
|
||||
iinfo->i_lenExtents =
|
||||
(iinfo->i_lenExtents + sb->s_blocksize - 1) &
|
||||
~(sb->s_blocksize - 1);
|
||||
~((u64)sb->s_blocksize - 1);
|
||||
}
|
||||
|
||||
add = 0;
|
||||
|
||||
Reference in New Issue
Block a user