]> dgit.raspbian.org Git - grub2.git/commit
fs/ext2: Fix out-of-bounds read for inline extents
authorMichael Chang <mchang@suse.com>
Fri, 31 May 2024 07:14:23 +0000 (15:14 +0800)
committerAurelien Jarno <aurel32@debian.org>
Thu, 30 Apr 2026 19:02:01 +0000 (21:02 +0200)
commit002af491e3c86511d2ddc62ca85eb02077e9f712
treea068680d7ad9507431e4917f6c2e61fd83396b2f
parentf0b9ea5d5fa25903f2083b564c73496472b2a5db
fs/ext2: Fix out-of-bounds read for inline extents

When inline extents are used, i.e. the extent tree depth equals zero,
a maximum of four entries can fit into the inode's data block. If the
extent header states a number of entries greater than four the current
ext2 implementation causes an out-of-bounds read. Fix this issue by
capping the number of extents to four when reading inline extents.

Reported-by: Daniel Axtens <dja@axtens.net>
Signed-off-by: Michael Chang <mchang@suse.com>
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
Gbp-Pq: Topic cve-2025-jan
Gbp-Pq: Name fs-ext2-Fix-out-of-bounds-read-for-inline-extents.patch
grub-core/fs/ext2.c