• Steve Magnani's avatar
    udf: prevent allocation beyond UDF partition · 56db1991
    Steve Magnani authored
    The UDF bitmap allocation code assumes that a recorded
    Unallocated Space Bitmap is compliant with ECMA-167 4/13,
    which requires that pad bytes between the end of the bitmap
    and the end of a logical block are all zero.
    
    When a recorded bitmap does not comply with this requirement,
    for example one padded with FF to the block boundary instead
    of 00, the allocator may "allocate" blocks that are outside
    the UDF partition extent. This can result in UDF volume descriptors
    being overwritten by file data or by partition-level descriptors,
    and in extreme cases, even in scribbling on a subsequent disk partition.
    
    Add a check that the block selected by the allocator actually
    resides within the UDF partition extent.
    Signed-off-by: default avatarSteven J. Magnani <steve@digidescorp.com>
    
    Link: https://lore.kernel.org/r/1564341552-129750-1-git-send-email-steve@digidescorp.comSigned-off-by: default avatarJan Kara <jack@suse.cz>
    56db1991
balloc.c 18.4 KB