Skip to content
  • Qu Wenruo's avatar
    btrfs: Fix wild memory access in compression level parser · eae8d825
    Qu Wenruo authored
    
    
    [BUG]
    Kernel panic when mounting with "-o compress" mount option.
    KASAN will report like:
    ------
    ==================================================================
    BUG: KASAN: wild-memory-access in strncmp+0x31/0xc0
    Read of size 1 at addr d86735fce994f800 by task mount/662
    ...
    Call Trace:
     dump_stack+0xe3/0x175
     kasan_report+0x163/0x370
     __asan_load1+0x47/0x50
     strncmp+0x31/0xc0
     btrfs_compress_str2level+0x20/0x70 [btrfs]
     btrfs_parse_options+0xff4/0x1870 [btrfs]
     open_ctree+0x2679/0x49f0 [btrfs]
     btrfs_mount+0x1b7f/0x1d30 [btrfs]
     mount_fs+0x49/0x190
     vfs_kern_mount.part.29+0xba/0x280
     vfs_kern_mount+0x13/0x20
     btrfs_mount+0x31e/0x1d30 [btrfs]
     mount_fs+0x49/0x190
     vfs_kern_mount.part.29+0xba/0x280
     do_mount+0xaad/0x1a00
     SyS_mount+0x98/0xe0
     entry_SYSCALL_64_fastpath+0x1f/0xbe
    ------
    
    [Cause]
    For 'compress' and 'compress_force' options, its token doesn't expect
    any parameter so its args[0] contains uninitialized data.
    Accessing args[0] will cause above wild memory access.
    
    [Fix]
    For Opt_compress and Opt_compress_force, set compression level to
    the default.
    
    Signed-off-by: default avatarQu Wenruo <wqu@suse.com>
    Reviewed-by: default avatarDavid Sterba <dsterba@suse.com>
    [ set the default in advance ]
    Signed-off-by: default avatarDavid Sterba <dsterba@suse.com>
    eae8d825