Revision 9dcbeed4d7e11e1dcf5e55475de3754f0855d1c2 authored by David Sterba on 09 November 2015, 10:44:45 UTC, committed by Chris Mason on 25 November 2015, 13:19:50 UTC
The calculation of range length in btrfs_sync_file leads to signed overflow. This was caught by PaX gcc SIZE_OVERFLOW plugin. https://forums.grsecurity.net/viewtopic.php?f=1&t=4284 The fsync call passes 0 and LLONG_MAX, the range length does not fit to loff_t and overflows, but the value is converted to u64 so it silently works as expected. The minimal fix is a typecast to u64, switching functions to take (start, end) instead of (start, len) would be more intrusive. Coccinelle script found that there's one more opencoded calculation of the length. <smpl> @@ loff_t start, end; @@ * end - start </smpl> CC: stable@vger.kernel.org Signed-off-by: David Sterba <dsterba@suse.com> Signed-off-by: Chris Mason <clm@fb.com>
1 parent d5f2e33
File | Mode | Size |
---|---|---|
apparmor | ||
integrity | ||
keys | ||
selinux | ||
smack | ||
tomoyo | ||
yama | ||
Kconfig | -rw-r--r-- | 5.6 KB |
Makefile | -rw-r--r-- | 900 bytes |
commoncap.c | -rw-r--r-- | 31.2 KB |
device_cgroup.c | -rw-r--r-- | 21.0 KB |
inode.c | -rw-r--r-- | 6.5 KB |
lsm_audit.c | -rw-r--r-- | 9.9 KB |
min_addr.c | -rw-r--r-- | 1.3 KB |
security.c | -rw-r--r-- | 53.1 KB |
![swh spinner](/static/img/swh-spinner.gif)
Computing file changes ...