diff options
| author | Mikulas Patocka <mpatocka@redhat.com> | 2026-09-30 18:42:20 +0200 |
|---|---|---|
| committer | Mikulas Patocka <mpatocka@redhat.com> | 2026-10-01 13:18:00 +0200 |
| commit | fc79aeb86a2c244c1f1894e2d8f2966fe2b60fa2 (patch) | |
| tree | 8a9658940f8f69942fc1311f939162aceff58bd6 /include/linux/hdlc | |
| parent | fcbde6227fcc53c73f08c56b2539e462d545cac6 (diff) | |
dm-integrity: validate the superblock on resume
dm_integrity_resume() re-reads the superblock from the device so that it
picks up the flags and the recalculate position. It performs no
validation on the result, while the constructor validates the superblock
it reads and sizes all the in-memory structures according to it. The user
may modify the superblock on the underlying device while the dm-integrity
device is suspended, so that the two no longer agree.
In particular, access_journal_data() shifts the journal entry index by
ic->sb->log2_sectors_per_block, while ic->journal_section_sectors and the
journal page list were computed with the value that was present at
constructor time. Increasing log2_sectors_per_block makes the index run
past the end of the journal, and dm-integrity then writes 512 bytes
through lowmem_page_address(NULL).
Snapshot the validated superblock in the constructor and refuse to resume
if any of the fields that describe the on-disk geometry changed.
Reported-by: syzbot+675c91651049ad042c5f@syzkaller.appspotmail.com
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Cc: stable@vger.kernel.org
Fixes: 118ba36e446c ("dm-integrity: fix recalculation in bitmap mode")
Assisted-by: Claude:claude-opus-5
Diffstat (limited to 'include/linux/hdlc')
0 files changed, 0 insertions, 0 deletions
