block/vmdk: fix OOB read in vmdk_read_extent()
Bounds check for marker.size doesn't account for the 12-byte marker header, allowing zlib to read past the allocated buffer. Move the check inside the has_marker block and subtract the marker size. Fixes: CVE-2026-2243 Reported-by: Halil Oktay (oblivionsage) <cookieandcream560@gmail.com> Signed-off-by: Halil Oktay (oblivionsage) <cookieandcream560@gmail.com> Reviewed-by: Kevin Wolf <kwolf@redhat.com> Signed-off-by: Kevin Wolf <kwolf@redhat.com>
Halil Oktay (oblivionsage) committed
Feb 10, 2026 at 13:33 UTC
cfda94eddb6c9c49b66461c950b22845a46a75c9
1 file changed
+4
-4
block/vmdk.c
+4
-4
@@ -1951,10 +1951,10 @@ vmdk_read_extent(VmdkExtent *extent, int64_t cluster_offset,
1951
marker = (VmdkGrainMarker *)cluster_buf;
1952
compressed_data = marker->data;
1953
data_len = le32_to_cpu(marker->size);
1954
- }
1955
- if (!data_len || data_len > buf_bytes) {
1956
- ret = -EINVAL;
1957
- goto out;
1954
+ if (!data_len || data_len > buf_bytes - sizeof(VmdkGrainMarker)) {
1955
+ ret = -EINVAL;
1956
+ goto out;
1957
+ }
1958
}
1959
ret = uncompress(uncomp_buf, &buf_len, compressed_data, data_len);
1960
if (ret != Z_OK) {