]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
nsfs: validate extensible ioctls
authorChristian Brauner <brauner@kernel.org>
Fri, 12 Sep 2025 11:52:26 +0000 (13:52 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sun, 19 Oct 2025 14:37:44 +0000 (16:37 +0200)
[ Upstream commit f8527a29f4619f74bc30a9845ea87abb9a6faa1e ]

Validate extensible ioctls stricter than we do now.

Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
fs/nsfs.c

index 59aa801347a7de7fc2ff4d04516381ecf1dfd2aa..34f0b35d3ead76d9af4729e073409428ad18f5e6 100644 (file)
--- a/fs/nsfs.c
+++ b/fs/nsfs.c
@@ -169,9 +169,11 @@ static bool nsfs_ioctl_valid(unsigned int cmd)
        /* Extensible ioctls require some extra handling. */
        switch (_IOC_NR(cmd)) {
        case _IOC_NR(NS_MNT_GET_INFO):
+               return extensible_ioctl_valid(cmd, NS_MNT_GET_INFO, MNT_NS_INFO_SIZE_VER0);
        case _IOC_NR(NS_MNT_GET_NEXT):
+               return extensible_ioctl_valid(cmd, NS_MNT_GET_NEXT, MNT_NS_INFO_SIZE_VER0);
        case _IOC_NR(NS_MNT_GET_PREV):
-               return (_IOC_TYPE(cmd) == _IOC_TYPE(cmd));
+               return extensible_ioctl_valid(cmd, NS_MNT_GET_PREV, MNT_NS_INFO_SIZE_VER0);
        }
 
        return false;