summaryrefslogtreecommitdiff
path: root/include/linux/hdlc
diff options
context:
space:
mode:
authorMikulas Patocka <mpatocka@redhat.com>2026-09-30 18:42:20 +0200
committerMikulas Patocka <mpatocka@redhat.com>2026-10-01 13:18:00 +0200
commitfc79aeb86a2c244c1f1894e2d8f2966fe2b60fa2 (patch)
tree8a9658940f8f69942fc1311f939162aceff58bd6 /include/linux/hdlc
parentfcbde6227fcc53c73f08c56b2539e462d545cac6 (diff)
dm-integrity: validate the superblock on resume
dm_integrity_resume() re-reads the superblock from the device so that it picks up the flags and the recalculate position. It performs no validation on the result, while the constructor validates the superblock it reads and sizes all the in-memory structures according to it. The user may modify the superblock on the underlying device while the dm-integrity device is suspended, so that the two no longer agree. In particular, access_journal_data() shifts the journal entry index by ic->sb->log2_sectors_per_block, while ic->journal_section_sectors and the journal page list were computed with the value that was present at constructor time. Increasing log2_sectors_per_block makes the index run past the end of the journal, and dm-integrity then writes 512 bytes through lowmem_page_address(NULL). Snapshot the validated superblock in the constructor and refuse to resume if any of the fields that describe the on-disk geometry changed. Reported-by: syzbot+675c91651049ad042c5f@syzkaller.appspotmail.com Signed-off-by: Mikulas Patocka <mpatocka@redhat.com> Cc: stable@vger.kernel.org Fixes: 118ba36e446c ("dm-integrity: fix recalculation in bitmap mode") Assisted-by: Claude:claude-opus-5
Diffstat (limited to 'include/linux/hdlc')
0 files changed, 0 insertions, 0 deletions