From nobody Mon May 16 21:34:06 2022 X-Original-To: fs@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id BF50A1AE9B0C for ; Mon, 16 May 2022 21:34:06 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4L2CDt3FF5z3G2s for ; Mon, 16 May 2022 21:34:06 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 5148A27E0D for ; Mon, 16 May 2022 21:34:06 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 24GLY6w0093287 for ; Mon, 16 May 2022 21:34:06 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 24GLY6F3093286 for fs@FreeBSD.org; Mon, 16 May 2022 21:34:06 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: fs@FreeBSD.org Subject: [Bug 263971] ffs: malicious superblock can cause buffer overflow during tasting: panic: vm_fault_lookup: fault on nofault entry, addr: 0xffffffc07cb67000 Date: Mon, 16 May 2022 21:34:06 +0000 X-Bugzilla-Reason: CC AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: Unspecified X-Bugzilla-Keywords: crash, needs-qa X-Bugzilla-Severity: Affects Some People X-Bugzilla-Who: rtm@lcs.mit.edu X-Bugzilla-Status: In Progress X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: fs@FreeBSD.org X-Bugzilla-Flags: maintainer-feedback? maintainer-feedback? mfc-stable13? mfc-stable12? X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated List-Id: Filesystems List-Archive: https://lists.freebsd.org/archives/freebsd-fs List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-fs@freebsd.org MIME-Version: 1.0 ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1652736846; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=3aqwMp4Hr65yHst0Pu6Fa7xPDjmqMwLrP0NQS8toGx8=; b=Ekf4Km2CZszFOWZiZoo5VXaV9axf6AJnn64HuSAM5089npjMDNA/PuseJbw5Jbulk8Rdb7 tR7q6Fzw2WSSH2S7VfVojXYIBr8VoTVDQiC8SKEN6Bf8TYo5RMTu6vzJ4AzdRUnutk0ltb timL3s5e6VlJX4TtmTrohYEj+7peO7edwiNAj2Fwq9KR+y7woxlBdz1UAVgQspvxgo1vl0 xYLljfFlYZa0joi1iNBzLYCKp78G0vKQ4XguhjssZRhu1Z96IIFV2VkfFYyLGgLyvJpUxv akBv8SUESJo8B0hVUZ/A9cDqYCuo4pxBnPRLTnO+A0gp2qKC711NtVmzxt2NYg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1652736846; a=rsa-sha256; cv=none; b=OS/tieB70tTx/iLMavjwBItVeYufQGQVAcgGkxgdnz9IXUJFViKK33JK/6H2GBqL1Gntoc 6ivPu9t0aVEClZBY1aY6MN+4AMGnwTLeVs3CItbOr19N3uTMcD1445IMuwMrlY6Cj03SUX DMDmK+1CAOG1zaic99sgOsxXm/thatYH7xBp+nlOQUE/JrMXt9d0eBiT9EthCuG67Gw0RU ql+FDxGVzA/+qcAiaHME+s/WwdDvkycq+3EZO4EaZKokCS8hGmX5QFXQWAXtuRiabbjUdJ alWa2FJ4JE80D4q/kK1YQ5fDeRnyFI8cVN5pwyMGDE+0tMUBj/hDaEEGWolUOw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-ThisMailContainsUnwantedMimeParts: N https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D263971 --- Comment #3 from Robert Morris --- (In reply to Kirk McKusick from comment #1) Even with validate_sblock(), the int32 size in ffs_sbget() can be made to wrap around. I've attached a disk image taste9f.img with fs_cssize 2021359616 fs_contigsumsize -1 ncg 126334728 so that this in ffs_sbget() size =3D fs->fs_cssize; size +=3D fs->fs_ncg * sizeof(u_int8_t); yields size =3D -2147272952 when I run mdconfig -f taste9f.img Then the process hangs in UFS_MALLOC(size). --=20 You are receiving this mail because: You are on the CC list for the bug. You are the assignee for the bug.=