Prevent creation of files larger than RLIMIT_FSIZE using fallocate. Currently using posix_fallocate one can bypass an RLIMIT_FSIZE limit and create a file larger than the limit. Add a check for new size in the fallocate system call. File-systems supporting fallocate such as ext4 are affected by this bug. Signed-off-by: Nikanth Karthikesan <knikanth@xxxxxxx> Reported-by: Eelis - <opensuse.org@xxxxxxxxxxxxxxxxxx> --- diff --git a/fs/open.c b/fs/open.c index 74e5cd9..95ce069 100644 --- a/fs/open.c +++ b/fs/open.c @@ -412,10 +412,14 @@ int do_fallocate(struct file *file, int mode, loff_t offset, loff_t len) if (!S_ISREG(inode->i_mode) && !S_ISDIR(inode->i_mode)) return -ENODEV; - /* Check for wrap through zero too */ - if (((offset + len) > inode->i_sb->s_maxbytes) || ((offset + len) < 0)) + /* Check for wrap through zero */ + if (offset+len < 0) return -EFBIG; + ret = inode_newsize_ok(inode, (offset + len)); + if (ret) + return ret; + if (!inode->i_op->fallocate) return -EOPNOTSUPP; -- To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html