hfsplus: fix NULL dereference in hfsplus_lookup() (CVE-2018-14617)
This commit is contained in:
parent
f84af2d0a0
commit
f21b10d326
|
@ -14,6 +14,7 @@ linux (4.18.6-2) UNRELEASED; urgency=medium
|
||||||
(Closes: #887045, #886292)
|
(Closes: #887045, #886292)
|
||||||
* btrfs: relocation: Only remove reloc rb_trees if reloc control has been
|
* btrfs: relocation: Only remove reloc rb_trees if reloc control has been
|
||||||
initialized (CVE-2018-14609)
|
initialized (CVE-2018-14609)
|
||||||
|
* hfsplus: fix NULL dereference in hfsplus_lookup() (CVE-2018-14617)
|
||||||
|
|
||||||
-- Ben Hutchings <ben@decadent.org.uk> Sat, 08 Sep 2018 23:24:31 +0100
|
-- Ben Hutchings <ben@decadent.org.uk> Sat, 08 Sep 2018 23:24:31 +0100
|
||||||
|
|
||||||
|
|
56
debian/patches/bugfix/all/hfsplus-fix-NULL-dereference-in-hfsplus_lookup.patch
vendored
Normal file
56
debian/patches/bugfix/all/hfsplus-fix-NULL-dereference-in-hfsplus_lookup.patch
vendored
Normal file
|
@ -0,0 +1,56 @@
|
||||||
|
From: =?UTF-8?q?Ernesto=20A=2E=20Fern=C3=A1ndez?=
|
||||||
|
<ernesto.mnd.fernandez@gmail.com>
|
||||||
|
Date: Thu, 23 Aug 2018 17:00:25 -0700
|
||||||
|
Subject: hfsplus: fix NULL dereference in hfsplus_lookup()
|
||||||
|
MIME-Version: 1.0
|
||||||
|
Content-Type: text/plain; charset=UTF-8
|
||||||
|
Content-Transfer-Encoding: 8bit
|
||||||
|
Origin: https://git.kernel.org/linus/a7ec7a4193a2eb3b5341243fc0b621c1ac9e4ec4
|
||||||
|
|
||||||
|
An HFS+ filesystem can be mounted read-only without having a metadata
|
||||||
|
directory, which is needed to support hardlinks. But if the catalog
|
||||||
|
data is corrupted, a directory lookup may still find dentries claiming
|
||||||
|
to be hardlinks.
|
||||||
|
|
||||||
|
hfsplus_lookup() does check that ->hidden_dir is not NULL in such a
|
||||||
|
situation, but mistakenly does so after dereferencing it for the first
|
||||||
|
time. Reorder this check to prevent a crash.
|
||||||
|
|
||||||
|
This happens when looking up corrupted catalog data (dentry) on a
|
||||||
|
filesystem with no metadata directory (this could only ever happen on a
|
||||||
|
read-only mount). Wen Xu sent the replication steps in detail to the
|
||||||
|
fsdevel list: https://bugzilla.kernel.org/show_bug.cgi?id=200297
|
||||||
|
|
||||||
|
Link: http://lkml.kernel.org/r/20180712215344.q44dyrhymm4ajkao@eaf
|
||||||
|
Signed-off-by: Ernesto A. Fernández <ernesto.mnd.fernandez@gmail.com>
|
||||||
|
Reported-by: Wen Xu <wen.xu@gatech.edu>
|
||||||
|
Cc: Viacheslav Dubeyko <slava@dubeyko.com>
|
||||||
|
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
|
||||||
|
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
|
||||||
|
---
|
||||||
|
fs/hfsplus/dir.c | 4 ++--
|
||||||
|
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/fs/hfsplus/dir.c b/fs/hfsplus/dir.c
|
||||||
|
index c5a70f83dbe7..f37662675c3a 100644
|
||||||
|
--- a/fs/hfsplus/dir.c
|
||||||
|
+++ b/fs/hfsplus/dir.c
|
||||||
|
@@ -77,13 +77,13 @@ static struct dentry *hfsplus_lookup(struct inode *dir, struct dentry *dentry,
|
||||||
|
cpu_to_be32(HFSP_HARDLINK_TYPE) &&
|
||||||
|
entry.file.user_info.fdCreator ==
|
||||||
|
cpu_to_be32(HFSP_HFSPLUS_CREATOR) &&
|
||||||
|
+ HFSPLUS_SB(sb)->hidden_dir &&
|
||||||
|
(entry.file.create_date ==
|
||||||
|
HFSPLUS_I(HFSPLUS_SB(sb)->hidden_dir)->
|
||||||
|
create_date ||
|
||||||
|
entry.file.create_date ==
|
||||||
|
HFSPLUS_I(d_inode(sb->s_root))->
|
||||||
|
- create_date) &&
|
||||||
|
- HFSPLUS_SB(sb)->hidden_dir) {
|
||||||
|
+ create_date)) {
|
||||||
|
struct qstr str;
|
||||||
|
char name[32];
|
||||||
|
|
||||||
|
--
|
||||||
|
2.19.0
|
||||||
|
|
|
@ -144,6 +144,7 @@ features/all/lockdown/arm64-add-kernel-config-option-to-lock-down-when.patch
|
||||||
debian/i386-686-pae-pci-set-pci-nobios-by-default.patch
|
debian/i386-686-pae-pci-set-pci-nobios-by-default.patch
|
||||||
bugfix/all/Revert-net-increase-fragment-memory-usage-limits.patch
|
bugfix/all/Revert-net-increase-fragment-memory-usage-limits.patch
|
||||||
bugfix/all/btrfs-relocation-Only-remove-reloc-rb_trees-if-reloc.patch
|
bugfix/all/btrfs-relocation-Only-remove-reloc-rb_trees-if-reloc.patch
|
||||||
|
bugfix/all/hfsplus-fix-NULL-dereference-in-hfsplus_lookup.patch
|
||||||
|
|
||||||
# Fix exported symbol versions
|
# Fix exported symbol versions
|
||||||
bugfix/all/module-disable-matching-missing-version-crc.patch
|
bugfix/all/module-disable-matching-missing-version-crc.patch
|
||||||
|
|
Loading…
Reference in New Issue