diff options
| author | Allan ELKAIM <[email protected]> | 2026-07-13 16:22:45 +0200 |
|---|---|---|
| committer | Tom Rini <[email protected]> | 2026-07-24 18:39:29 -0600 |
| commit | 57e0bb7bf00dadd7537f93609afb955108ce22c7 (patch) | |
| tree | 3243889f2de6d51a4ae553c70c016f136896756f | |
| parent | 9a9d46cb5e1a8f600c52f3ddaeaca8d4f28f66ee (diff) | |
fs/squashfs: add sqfs_dir_offset() error checks
sqfs_dir_offset() returns a negative errno on failure, but three
call sites in sqfs_search_dir() use the return value as an array
index without checking for errors first. If the lookup fails,
dirs->table is set to an invalid address, leading to undefined
behavior.
Add negative-value guards after each sqfs_dir_offset() call so
that any lookup failure propagates cleanly as an error rather
than producing incorrect results.
Note: the corresponding sqfs_find_inode() NULL checks and the
heap exhaustion fix during symlink resolution are applied in
separate patches.
Acked-by: Miquel Raynal <[email protected]>
Reviewed-by: Richard Genoud <[email protected]>
Signed-off-by: Allan ELKAIM <[email protected]>
| -rw-r--r-- | fs/squashfs/sqfs.c | 14 |
1 files changed, 14 insertions, 0 deletions
diff --git a/fs/squashfs/sqfs.c b/fs/squashfs/sqfs.c index 07e2bd82561..af32d008e30 100644 --- a/fs/squashfs/sqfs.c +++ b/fs/squashfs/sqfs.c @@ -496,6 +496,8 @@ static int sqfs_search_dir(struct squashfs_dir_stream *dirs, char **token_list, /* get directory offset in directory table */ offset = sqfs_dir_offset(table, m_list, m_count); + if (offset < 0) + return offset; dirs->table = &dirs->dir_table[offset]; /* Setup directory header */ @@ -627,6 +629,12 @@ static int sqfs_search_dir(struct squashfs_dir_stream *dirs, char **token_list, /* Get dir. offset into the directory table */ offset = sqfs_dir_offset(table, m_list, m_count); + if (offset < 0) { + free(dirs->entry); + dirs->entry = NULL; + ret = offset; + goto out; + } dirs->table = &dirs->dir_table[offset]; /* Copy directory header */ @@ -651,6 +659,12 @@ static int sqfs_search_dir(struct squashfs_dir_stream *dirs, char **token_list, } offset = sqfs_dir_offset(table, m_list, m_count); + if (offset < 0) { + free(dirs->entry); + dirs->entry = NULL; + ret = offset; + goto out; + } dirs->table = &dirs->dir_table[offset]; if (get_unaligned_le16(&dir->inode_type) == SQFS_DIR_TYPE) |
