From: Mikulas Patocka <[email protected]>

commit 31d6e6c0ba8d5a7bd59660035a089307100c5e8e upstream.

There's a buffer overflow in dm-verity-fec:

if (neras && *neras <= v->fec->roots)
        fio->erasures[(*neras)++] = i;

This allows *neras to reach roots + 1 (the post-increment pushes it past
roots). This value is then passed as no_eras to decode_rs8(). Inside the
RS decoder (lib/reed_solomon/decode_rs.c:113-121), the erasure locator
polynomial loop writes lambda[j] where j can reach nroots + 1 — one
element past the end of lambda[] (which is sized nroots + 1, valid
indices 0..nroots). The out-of-bounds write lands on syn[0], corrupting
the syndrome buffer.

Signed-off-by: Mikulas Patocka <[email protected]>
Assisted-by: Claude:claude-opus-4-6
Cc: [email protected]
Fixes: a739ff3f543a ("dm verity: add support for forward error correction")
Reviewed-by: Sami Tolvanen <[email protected]>
Signed-off-by: Mikulas Patocka <[email protected]>
Signed-off-by: Eric Biggers <[email protected]>
---
 drivers/md/dm-verity-fec.c | 4 ++--
 drivers/md/dm-verity-fec.h | 2 +-
 2 files changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/md/dm-verity-fec.c b/drivers/md/dm-verity-fec.c
index cebcc8fd25d70..d1e4fbc5a21d9 100644
--- a/drivers/md/dm-verity-fec.c
+++ b/drivers/md/dm-verity-fec.c
@@ -250,7 +250,7 @@ static int fec_read_bufs(struct dm_verity *v, struct 
dm_verity_io *io,
                                     (unsigned long long)block, PTR_ERR(bbuf));
 
                        /* assume the block is corrupted */
-                       if (neras && *neras <= v->fec->roots)
+                       if (neras && *neras < v->fec->roots)
                                fio->erasures[(*neras)++] = i;
 
                        continue;
@@ -268,7 +268,7 @@ static int fec_read_bufs(struct dm_verity *v, struct 
dm_verity_io *io,
                         * skip if we have already found the theoretical
                         * maximum number (i.e. fec->roots) of erasures
                         */
-                       if (neras && *neras <= v->fec->roots &&
+                       if (neras && *neras < v->fec->roots &&
                            fec_is_erasure(v, io, want_digest, bbuf))
                                fio->erasures[(*neras)++] = i;
                }
diff --git a/drivers/md/dm-verity-fec.h b/drivers/md/dm-verity-fec.h
index b3460103e0e10..8552b5d3c9152 100644
--- a/drivers/md/dm-verity-fec.h
+++ b/drivers/md/dm-verity-fec.h
@@ -50,7 +50,7 @@ struct dm_verity_fec {
 /* per-bio data */
 struct dm_verity_fec_io {
        struct rs_control *rs;  /* Reed-Solomon state */
-       int erasures[DM_VERITY_FEC_MAX_ROOTS + 1]; /* erasures for decode_rs8 */
+       int erasures[DM_VERITY_FEC_MAX_ROOTS]; /* erasures for decode_rs8 */
        u8 *bufs[DM_VERITY_FEC_BUF_MAX];        /* bufs for deinterleaving */
        unsigned int nbufs;             /* number of buffers allocated */
        u8 *output;             /* buffer for corrected output */
-- 
2.55.0


Reply via email to