]> git.ipfire.org Git - thirdparty/u-boot.git/commitdiff
fs/squashfs: add sqfs_dir_offset() error checks
authorAllan ELKAIM <allan.elkaim@gmail.com>
Mon, 13 Jul 2026 14:22:45 +0000 (16:22 +0200)
committerTom Rini <trini@konsulko.com>
Sat, 25 Jul 2026 00:39:29 +0000 (18:39 -0600)
sqfs_dir_offset() returns a negative errno on failure, but three
call sites in sqfs_search_dir() use the return value as an array
index without checking for errors first. If the lookup fails,
dirs->table is set to an invalid address, leading to undefined
behavior.

Add negative-value guards after each sqfs_dir_offset() call so
that any lookup failure propagates cleanly as an error rather
than producing incorrect results.

Note: the corresponding sqfs_find_inode() NULL checks and the
heap exhaustion fix during symlink resolution are applied in
separate patches.

Acked-by: Miquel Raynal <miquel.raynal@bootlin.com>
Reviewed-by: Richard Genoud <richard.genoud@bootlin.com>
Signed-off-by: Allan ELKAIM <allan.elkaim@gmail.com>
fs/squashfs/sqfs.c

index 07e2bd8256188977453be111ffda4fc4aca08064..af32d008e30dd8e3d659f2e79650b41b57e81d4c 100644 (file)
@@ -496,6 +496,8 @@ static int sqfs_search_dir(struct squashfs_dir_stream *dirs, char **token_list,
 
        /* get directory offset in directory table */
        offset = sqfs_dir_offset(table, m_list, m_count);
+       if (offset < 0)
+               return offset;
        dirs->table = &dirs->dir_table[offset];
 
        /* Setup directory header */
@@ -627,6 +629,12 @@ static int sqfs_search_dir(struct squashfs_dir_stream *dirs, char **token_list,
 
                /* Get dir. offset into the directory table */
                offset = sqfs_dir_offset(table, m_list, m_count);
+               if (offset < 0) {
+                       free(dirs->entry);
+                       dirs->entry = NULL;
+                       ret = offset;
+                       goto out;
+               }
                dirs->table = &dirs->dir_table[offset];
 
                /* Copy directory header */
@@ -651,6 +659,12 @@ static int sqfs_search_dir(struct squashfs_dir_stream *dirs, char **token_list,
        }
 
        offset = sqfs_dir_offset(table, m_list, m_count);
+       if (offset < 0) {
+               free(dirs->entry);
+               dirs->entry = NULL;
+               ret = offset;
+               goto out;
+       }
        dirs->table = &dirs->dir_table[offset];
 
        if (get_unaligned_le16(&dir->inode_type) == SQFS_DIR_TYPE)