diff options
author | Alden Tondettar <alden.tondettar@gmail.com> | 2016-04-26 05:27:56 +0300 |
---|---|---|
committer | Jan Kara <jack@suse.cz> | 2016-04-26 09:25:07 +0300 |
commit | a47241cdeee2689ee7089ec95cadfcf66588fbdb (patch) | |
tree | 78565c734b29f102c1d1350f71aae947cda8593e /fs/hfs/attr.c | |
parent | c26f6c61578852f679787d555e6d07804e1f5f14 (diff) | |
download | linux-a47241cdeee2689ee7089ec95cadfcf66588fbdb.tar.xz |
udf: Prevent stack overflow on corrupted filesystem mount
Presently, a corrupted or malicious UDF filesystem containing a very large
number (or cycle) of Logical Volume Integrity Descriptor extent
indirections may trigger a stack overflow and kernel panic in
udf_load_logicalvolint() on mount.
Replace the unnecessary recursion in udf_load_logicalvolint() with
simple iteration. Set an arbitrary limit of 1000 indirections (which would
have almost certainly overflowed the stack without this fix), and treat
such cases as if there were no LVID.
Signed-off-by: Alden Tondettar <alden.tondettar@gmail.com>
Signed-off-by: Jan Kara <jack@suse.cz>
Diffstat (limited to 'fs/hfs/attr.c')
0 files changed, 0 insertions, 0 deletions