mainline inclusion from mainline-v7.2-rc2 commit 55ec50d046c03b3724741957f7b007856e36dbe7 category: bugfix bugzilla: https://atomgit.com/src-openeuler/kernel/issues/17916 CVE: CVE-2026-72367 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=... -------------------------------- iomap: fix zero padding data issue in concurrent append writes changed ioend accounting so that io_size tracks only valid data within EOF. This trims io_size when a writeback range extends past end_pos: ioend->io_size += map_len; if (ioend->io_offset + ioend->io_size > end_pos) ioend->io_size = end_pos - ioend->io_offset; However, if end_pos ends up below ioend->io_offset, the subtraction becomes negative and is stored in size_t io_size, causing an unsigned wrap to a huge value. This can happen when writeback continues past byte-level EOF up to a block-aligned range, or when a concurrent truncate shrinks the file after end_pos was sampled in iomap_writeback_handle_eof(). A wrapped io_size can mislead append detection and corrupt completion-time size handling, since filesystem end_io paths consume io_size for decisions such as on-disk EOF updates and unwritten/COW completion ranges. Fix this by clamping io_size to zero when EOF has moved to or before the ioend start offset. This preserves the original intent of trimming io_size to valid in-EOF data while avoiding the underflow. Fixes: 51d20d1dacbe ("iomap: fix zero padding data issue in concurrent append writes") Suggested-by: Christoph Hellwig <hch@lst.de> Signed-off-by: Morduan Zang <zhangdandan@uniontech.com> Link: https://patch.msgid.link/9E38E2659B47DC2A+20260624062622.337469-1-zhangdanda... Reviewed-by: Christoph Hellwig <hch@lst.de> Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org> Conflicts: fs/iomap/buffered-io.c [5fcbd555d483 ("iomap: split bios to zone append limits in the submission handlers") not merged.] Signed-off-by: Ran Hongyun <ranhongyun1@huawei.com> --- fs/iomap/buffered-io.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/fs/iomap/buffered-io.c b/fs/iomap/buffered-io.c index 1b9177ad7cdd..baa7bbe02fad 100644 --- a/fs/iomap/buffered-io.c +++ b/fs/iomap/buffered-io.c @@ -2002,8 +2002,12 @@ static int iomap_add_to_ioend(struct iomap_writepage_ctx *wpc, * should not be trimmed in such cases. */ wpc->ioend->io_size += len; - if (pos < isize && pos + len > isize) - wpc->ioend->io_size = isize - wpc->ioend->io_offset; + if (wpc->ioend->io_offset + wpc->ioend->io_size > isize) { + if (wpc->ioend->io_offset >= isize) + wpc->ioend->io_size = 0; + else + wpc->ioend->io_size = isize - wpc->ioend->io_offset; + } wbc_account_cgroup_owner(wbc, &folio->page, len); return 0; -- 2.52.0