]> git.itanic.dy.fi Git - linux-stable/commitdiff
ext4: disallow ea_inodes with extended attributes
authorTheodore Ts'o <tytso@mit.edu>
Wed, 24 May 2023 03:49:50 +0000 (23:49 -0400)
committerTheodore Ts'o <tytso@mit.edu>
Tue, 30 May 2023 19:33:57 +0000 (15:33 -0400)
An ea_inode stores the value of an extended attribute; it can not have
extended attributes itself, or this will cause recursive nightmares.
Add a check in ext4_iget() to make sure this is the case.

Cc: stable@kernel.org
Reported-by: syzbot+e44749b6ba4d0434cd47@syzkaller.appspotmail.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Link: https://lore.kernel.org/r/20230524034951.779531-4-tytso@mit.edu
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
fs/ext4/inode.c

index 258f3cbed347c6cfa1f41f9e9b140718eca692fd..02de439bf1f04ee7b9ab25bc2caf4c4e1fce610a 100644 (file)
@@ -4647,6 +4647,9 @@ static const char *check_igot_inode(struct inode *inode, ext4_iget_flags flags)
        if (flags & EXT4_IGET_EA_INODE) {
                if (!(EXT4_I(inode)->i_flags & EXT4_EA_INODE_FL))
                        return "missing EA_INODE flag";
+               if (ext4_test_inode_state(inode, EXT4_STATE_XATTR) ||
+                   EXT4_I(inode)->i_file_acl)
+                       return "ea_inode with extended attributes";
        } else {
                if ((EXT4_I(inode)->i_flags & EXT4_EA_INODE_FL))
                        return "unexpected EA_INODE flag";