GFS2: make sure fallocate bytes is a multiple of blksize, CVE-2011-2689
authorBenjamin Marzinski <bmarzins@redhat.com>
Tue, 2 Aug 2011 09:31:59 +0000 (10:31 +0100)
committerTim Gardner <tim.gardner@canonical.com>
Tue, 2 Aug 2011 12:56:44 +0000 (06:56 -0600)
commitf79f0d05d67c9f8fec7fae0415df34b06fd532ce
tree5b977446e2e6c5d15b1905b3045a5b12dfe84d89
parentc1c3252ce9e1853d23b5e7b128acbdb4d9594f09
GFS2: make sure fallocate bytes is a multiple of blksize, CVE-2011-2689

The GFS2 fallocate code chooses a target size to for allocating chunks of
space.  Whenever it can't find any resource groups with enough space free, it
halves its target. Since this target is in bytes, eventually it will no longer
be a multiple of blksize.  As long as there is more space available in the
resource group than the target, this isn't a problem, since gfs2 will use the
actual space available, which is always a multiple of blksize.  However,
when gfs couldn't fallocate a bigger chunk than the target, it was using the
non-blksize aligned number. This caused a BUG in later code that required
blksize aligned offsets.  GFS2 now ensures that bytes is always a multiple of
blksize

Signed-off-by: Benjamin Marzinski <bmarzins@redhat.com>
Signed-off-by: Steven Whitehouse <swhiteho@redhat.com>
(cherry picked from commit 6905d9e4dda6112f007e9090bca80507da158e63)
CVE-2011-2689
BugLink: http://bugs.launchpad.net/bugs/819572
Signed-off-by: Andy Whitcroft <apw@canonical.com>
Acked-by: Stefan Bader <stefan.bader@canonical.com>
Signed-off-by: Tim Gardner <tim.gardner@canonical.com>
fs/gfs2/file.c