summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorAllan ELKAIM <[email protected]>2026-07-13 16:22:45 +0200
committerTom Rini <[email protected]>2026-07-24 18:39:29 -0600
commit57e0bb7bf00dadd7537f93609afb955108ce22c7 (patch)
tree3243889f2de6d51a4ae553c70c016f136896756f
parent9a9d46cb5e1a8f600c52f3ddaeaca8d4f28f66ee (diff)
fs/squashfs: add sqfs_dir_offset() error checks
sqfs_dir_offset() returns a negative errno on failure, but three call sites in sqfs_search_dir() use the return value as an array index without checking for errors first. If the lookup fails, dirs->table is set to an invalid address, leading to undefined behavior. Add negative-value guards after each sqfs_dir_offset() call so that any lookup failure propagates cleanly as an error rather than producing incorrect results. Note: the corresponding sqfs_find_inode() NULL checks and the heap exhaustion fix during symlink resolution are applied in separate patches. Acked-by: Miquel Raynal <[email protected]> Reviewed-by: Richard Genoud <[email protected]> Signed-off-by: Allan ELKAIM <[email protected]>
-rw-r--r--fs/squashfs/sqfs.c14
1 files changed, 14 insertions, 0 deletions
diff --git a/fs/squashfs/sqfs.c b/fs/squashfs/sqfs.c
index 07e2bd82561..af32d008e30 100644
--- a/fs/squashfs/sqfs.c
+++ b/fs/squashfs/sqfs.c
@@ -496,6 +496,8 @@ static int sqfs_search_dir(struct squashfs_dir_stream *dirs, char **token_list,
/* get directory offset in directory table */
offset = sqfs_dir_offset(table, m_list, m_count);
+ if (offset < 0)
+ return offset;
dirs->table = &dirs->dir_table[offset];
/* Setup directory header */
@@ -627,6 +629,12 @@ static int sqfs_search_dir(struct squashfs_dir_stream *dirs, char **token_list,
/* Get dir. offset into the directory table */
offset = sqfs_dir_offset(table, m_list, m_count);
+ if (offset < 0) {
+ free(dirs->entry);
+ dirs->entry = NULL;
+ ret = offset;
+ goto out;
+ }
dirs->table = &dirs->dir_table[offset];
/* Copy directory header */
@@ -651,6 +659,12 @@ static int sqfs_search_dir(struct squashfs_dir_stream *dirs, char **token_list,
}
offset = sqfs_dir_offset(table, m_list, m_count);
+ if (offset < 0) {
+ free(dirs->entry);
+ dirs->entry = NULL;
+ ret = offset;
+ goto out;
+ }
dirs->table = &dirs->dir_table[offset];
if (get_unaligned_le16(&dir->inode_type) == SQFS_DIR_TYPE)