{
    "version": 1,
    "title": "KASAN: slab-out-of-bounds Write in hfs_asc2mac",
    "display-title": "KASAN: slab-out-of-bounds Write in hfs_asc2mac",
    "id": "67d3719a7490d99812faae7f9c2c26e9f386c1a6",
    "status": "fixed",
    "fix-commits": [
        {
            "title": "hfs: Fix OOB Write in hfs_asc2mac",
            "link": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c53ed55cb275344086e32a7080a6b19cb183650b",
            "hash": "c53ed55cb275344086e32a7080a6b19cb183650b",
            "repo": "git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git",
            "branch": "master"
        }
    ],
    "discussions": [
        "https://lore.kernel.org/all/00000000000086b19705ee486240@google.com/T/",
        "https://lore.kernel.org/all/20221126043612.853428-1-zhangpeng362@huawei.com/T/",
        "https://lore.kernel.org/all/20221129090706.2336748-1-zhangpeng362@huawei.com/T/",
        "https://lore.kernel.org/all/20221202030038.1391945-1-zhangpeng362@huawei.com/T/"
    ],
    "crashes": [
        {
            "title": "KASAN: slab-out-of-bounds Write in hfs_asc2mac",
            "syz-reproducer": "/text?tag=ReproSyz&x=13e49a3d880000",
            "c-reproducer": "/text?tag=ReproC&x=11a15a73880000",
            "kernel-config": "/text?tag=KernelConfig&x=8d01b6e3197974dd",
            "kernel-source-git": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/log/?id=4312098baf37ee17a8350725e6e0d0e8590252d4",
            "kernel-source-commit": "4312098baf37ee17a8350725e6e0d0e8590252d4",
            "syzkaller-git": "https://github.com/google/syzkaller/commits/ff68ff8f0e1a62984fe933655e14994ae3e16809",
            "syzkaller-commit": "ff68ff8f0e1a62984fe933655e14994ae3e16809",
            "compiler-description": "Debian clang version 13.0.1-++20220126092033+75e33f71c2da-1~exp1~20220126212112.63, GNU ld (GNU Binutils for Debian) 2.35.2",
            "architecture": "amd64",
            "crash-report-link": "/text?tag=CrashReport&x=14107a05880000"
        }
    ],
    "patch_modified_functions": [
        [
            "hfs_asc2mac",
            "fs/hfs/trans.c"
        ]
    ],
    "patch_commit_date": "2022-12-02T03:00:38+00:00",
    "cause_commit_date": null,
    "subsystems": [
        "hfs"
    ],
    "parent_of_fix_commit": "8d824e69d9f3fa3121b2dda25053bae71e2460d2",
    "patch": "diff --git a/fs/hfs/trans.c b/fs/hfs/trans.c\nindex 39f5e343bf4d..fdb0edb8a607 100644\n--- a/fs/hfs/trans.c\n+++ b/fs/hfs/trans.c\n@@ -109,7 +109,7 @@ void hfs_asc2mac(struct super_block *sb, struct hfs_name *out, const struct qstr\n \tif (nls_io) {\n \t\twchar_t ch;\n \n-\t\twhile (srclen > 0) {\n+\t\twhile (srclen > 0 && dstlen > 0) {\n \t\t\tsize = nls_io->char2uni(src, srclen, &ch);\n \t\t\tif (size < 0) {\n \t\t\t\tch = '?';\n",
    "patch_modified_files": [
        "fs/hfs/trans.c"
    ]
}