[PATCH v2] fs/erofs: fix an integer overflow in symlink resolution

Tom Rini trini at konsulko.com
Wed Feb 19 10:30:55 AEDT 2025


On Tue, Feb 18, 2025 at 03:24:08PM -0800, Jonathan Bar Or wrote:
> That's great! Thank you for your work!
> 
> Any expected fixes on the other issues I raised Tom?
> I'm asking specifically because GRUB2 maintainers are working on
> solving very similar issues in their repository for SquashFS (being
> rolled out right now).
> It'd be best to solve ASAP as people might realize the similarities
> between GRUB2 and U-boot in that module.

Adding back in the squashfs maintainers.

> 
> Best regards,
>            Jonathan
> 
> On Tue, Feb 18, 2025 at 11:35 AM Tom Rini <trini at konsulko.com> wrote:
> >
> > On Thu, 13 Feb 2025 19:28:47 +0800, Gao Xiang wrote:
> >
> > > See the original report [1], otherwise len + 1 will be overflowed.
> > >
> > > Note that EROFS archive can record arbitary symlink sizes in principle,
> > > so we don't assume a short number like 4096.
> > >
> > > [1] https://lore.kernel.org/r/20250210164151.GN1233568@bill-the-cat
> > >
> > > [...]
> >
> > Applied to u-boot/master, thanks!
> >
> > --
> > Tom
> >
> >

-- 
Tom
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 659 bytes
Desc: not available
URL: <http://lists.ozlabs.org/pipermail/linux-erofs/attachments/20250218/a1435a29/attachment.sig>


More information about the Linux-erofs mailing list