Received: by 2002:a6b:500f:0:0:0:0:0 with SMTP id e15csp4419506iob; Sun, 8 May 2022 12:06:50 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwLcKEFbb0ov+CAE5AP5q1wCK4qhh1IOSIzhujklGWhfaSwdAPY+HcKXKLieD/Eo7clHksT X-Received: by 2002:a17:907:2d8d:b0:6f8:5c3c:7217 with SMTP id gt13-20020a1709072d8d00b006f85c3c7217mr6962421ejc.1.1652036810571; Sun, 08 May 2022 12:06:50 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1652036810; cv=none; d=google.com; s=arc-20160816; b=Y5RsYSGKQn5fGJ4F3lpEFzN1Pog4jDsK/emvuibgg2yvKULRRH6LiZoHDclNR3TOqJ i4mWQ7y2Tu1xzzVv9N1DCF+apoUdFJC6YVibFf2UQqtlRqOMHZSTpYBIqMXWQy9ALZmy meo+aVw7iagqcbUGTunu+jBBYAUMbgBo0OOiKUTemKSTa6FsIWsw+icYSZrM677gu5NC 79LWM4C5BGR03O34UlxKG+t4rAbLc+E9EWcZ7fVr9xrOAAQ2Vqj6Oi8POVufJkllOIr5 wGJ7MqYl+F3XX0JDdbbS7y5SsugUidVE5Xk21vDSVX2YCdjBZTtzcyAiHxxrJ6X27v/s kXcg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:from:dkim-signature; bh=0GBnsUFI480KyuDDKiDj6EO0c5V7IXRlhq6lrsQR2EY=; b=YRgKknEpDRa2ZhlI199VFyePFAuzzNbQtZyVeGtCroTbENC3h6nVgZdYh2Ueb/rXx1 Ihwml2NIg0UrZnydKy3I61A9z0dHwEJAgV82Ys+u75ReX1yizOoFJwHeRuCTJ3/FbGLG oFx59BqQmlqewWQSdSVtj9ZOt548Ec+buqaXOaxF+SFuUlsQVN+zPjWcqOI45qTkl9f9 Km801d5A1xVrZFF2pfqLoi3UbGBEe38xwLdqVFeUhdIjR4YTb7LxuM5+FUmMciZC4yT1 11b4lytUhf/nQBQ3CBWfYrhPYRxNdcUO21rT/KrKUJNE1XFsRDkEfp7dT3LWRQAzfMby fZ7A== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=k7uvdMBT; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id sb6-20020a1709076d8600b006f90d9bc9a2si4372229ejc.463.2022.05.08.12.06.27; Sun, 08 May 2022 12:06:50 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=k7uvdMBT; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1388828AbiEFDuz (ORCPT + 99 others); Thu, 5 May 2022 23:50:55 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:49968 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1388627AbiEFDuq (ORCPT ); Thu, 5 May 2022 23:50:46 -0400 Received: from mail-pg1-x533.google.com (mail-pg1-x533.google.com [IPv6:2607:f8b0:4864:20::533]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id ADEF2443E1 for ; Thu, 5 May 2022 20:47:04 -0700 (PDT) Received: by mail-pg1-x533.google.com with SMTP id x12so5132141pgj.7 for ; Thu, 05 May 2022 20:47:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=0GBnsUFI480KyuDDKiDj6EO0c5V7IXRlhq6lrsQR2EY=; b=k7uvdMBTxQMDq6M3LascyGTaiuxi2yT1elp1Bszljqv5oQ019q15F7QRpLZ+v1AwDR lO7ycwTQEmQQSfqcXkDIXY3Diu5PwWZmmgNHECwmCVNcXktbcpsr/CEtiOvs6y2orAk/ SkMqSa4AXgPTI36JKkzNiGI47w67B2KjdIxEy/jk2jiLCJkAa7CQGY/OJdehRZLn72ca aVBe6NaCeqffUuvNNxvTBYNjI+uipnvNQKhXi5Uo9qhgPv6zfBIdVlFT7pX7Xwy2z8u/ PqAisoU/4c+03vj7Hb2QgV8gxPPQJALYjiTG/WCMwlXqqjtNTK+IxyJ1rUt+uzsKqnmJ A1Wg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=0GBnsUFI480KyuDDKiDj6EO0c5V7IXRlhq6lrsQR2EY=; b=0vgh8y9lKqlhp4W5dCqMMLlVULEX6CyD69pU6GEzU5MlUCneDcOki80YYA/3fEqIGY zAimJY2uaP2ldt+zxsmwA7BZbDKHFm6eRFK/AwjJQbfS2SkXP/s6P04pKRUmqwu6913e KgcnjPuXAWfCCFOQWqXx/ghPYTe0dT/q56HzUElLB87yVmlodFiMR4eSunkMT2RBRExm PXbcFWc8ytVJkMcBCf1EZPj04uVuhzi7rYxzYSE3KxEVk/V9LacRUcn6rvSqxpI7xW1K I7ML1ki/YcetK6CXLONe/ckffMFil4wN5YhhesVJjdRakLJN4m25YG/rhnWsksp9F/GC q0hw== X-Gm-Message-State: AOAM531TQZltiCGoB95BupbO5JLWpnOE8HZem8adq4FGfjx9N4r7Jx7e +VHjrJ1ubukfvNFGEEo9GLc= X-Received: by 2002:aa7:962e:0:b0:50d:5ed8:aa23 with SMTP id r14-20020aa7962e000000b0050d5ed8aa23mr1602069pfg.43.1651808824217; Thu, 05 May 2022 20:47:04 -0700 (PDT) Received: from lbmac.lan ([119.28.81.66]) by smtp.gmail.com with ESMTPSA id p18-20020a1709028a9200b0015e8d4eb2cdsm398139plo.279.2022.05.05.20.47.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 05 May 2022 20:47:03 -0700 (PDT) From: Liangbin Lian To: ntfs3@lists.linux.dev, almaz.alexandrovich@paragon-software.com Cc: linux-kernel@vger.kernel.org, Liangbin Lian Subject: [PATCH] fs/ntfs3: fix null pointer dereference in d_flags_for_inode Date: Fri, 6 May 2022 11:46:56 +0800 Message-Id: <20220506034656.50038-1-jjm2473@gmail.com> X-Mailer: git-send-email 2.32.0 (Apple Git-132) MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-1.7 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_ENVFROM_END_DIGIT, FREEMAIL_FROM,RCVD_IN_DNSWL_NONE,RCVD_IN_SBL,SPF_HELO_NONE,SPF_PASS, T_SCC_BODY_TEXT_LINE autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org ntfs_read_mft may return inode with null i_op, cause null pointer dereference in d_flags_for_inode (inode->i_op->get_link). Reproduce: - sudo mount -t ntfs3 -o loop ntfs.img ntfs - ls ntfs/'$Extend/$Quota' The call trace is shown below (striped): BUG: kernel NULL pointer dereference, address: 0000000000000008 CPU: 0 PID: 577 Comm: ls Tainted: G OE 5.16.0-0.bpo.4-amd64 #1 Debian 5.16.12-1~bpo11+1 RIP: 0010:d_flags_for_inode+0x65/0x90 Call Trace: ntfs_lookup +--- dir_search_u | +--- ntfs_iget5 | +--- ntfs_read_mft +--- d_splice_alias +--- __d_add +--- d_flags_for_inode Signed-off-by: Liangbin Lian --- fs/ntfs3/inode.c | 1 - 1 file changed, 1 deletion(-) diff --git a/fs/ntfs3/inode.c b/fs/ntfs3/inode.c index 9eab11e3b..b68d26fa8 100644 --- a/fs/ntfs3/inode.c +++ b/fs/ntfs3/inode.c @@ -45,7 +45,6 @@ static struct inode *ntfs_read_mft(struct inode *inode, struct MFT_REC *rec; struct runs_tree *run; - inode->i_op = NULL; /* Setup 'uid' and 'gid' */ inode->i_uid = sbi->options->fs_uid; inode->i_gid = sbi->options->fs_gid; -- 2.32.0 (Apple Git-132)