]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
jfs: Verify inode mode when loading from disk
authorTetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Fri, 12 Sep 2025 14:18:44 +0000 (23:18 +0900)
committerDave Kleikamp <dave.kleikamp@oracle.com>
Thu, 18 Sep 2025 14:08:11 +0000 (09:08 -0500)
The inode mode loaded from corrupted disk can be invalid. Do like what
commit 0a9e74051313 ("isofs: Verify inode mode when loading from disk")
does.

Reported-by: syzbot <syzbot+895c23f6917da440ed0d@syzkaller.appspotmail.com>
Closes: https://syzkaller.appspot.com/bug?extid=895c23f6917da440ed0d
Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Signed-off-by: Dave Kleikamp <dave.kleikamp@oracle.com>
fs/jfs/inode.c

index fcedeb514e14ae1a20af8325107de5a6c06fe0eb..21f3d029da7dd5d4846aaa942a94198380847353 100644 (file)
@@ -59,9 +59,15 @@ struct inode *jfs_iget(struct super_block *sb, unsigned long ino)
                         */
                        inode->i_link[inode->i_size] = '\0';
                }
-       } else {
+       } else if (S_ISCHR(inode->i_mode) || S_ISBLK(inode->i_mode) ||
+                  S_ISFIFO(inode->i_mode) || S_ISSOCK(inode->i_mode)) {
                inode->i_op = &jfs_file_inode_operations;
                init_special_inode(inode, inode->i_mode, inode->i_rdev);
+       } else {
+               printk(KERN_DEBUG "JFS: Invalid file type 0%04o for inode %lu.\n",
+                      inode->i_mode, inode->i_ino);
+               iget_failed(inode);
+               return ERR_PTR(-EIO);
        }
        unlock_new_inode(inode);
        return inode;