Description: Fix integer overflow in rgrp allocation size (CVE-2026-71223)
 The resource group (rgrp) allocation size is computed as
 rt_length * sd_bsize where both operands are 32-bit.  rt_length comes
 from the on-disk rindex and is not otherwise bounded, so on 32-bit
 platforms (and for oversized rgrps on 64-bit) this multiplication can
 overflow, producing an undersized buffer allocation that is later
 accessed using the full rt_length, resulting in an out-of-bounds
 read/write.
 .
 Perform the size computation in size_t arithmetic and reject resource
 groups whose size cannot be represented before allocating.
Author: Valentin Vidic <vvidic@debian.org>
Last-Update: 2026-10-06
---
This patch header follows DEP-3: http://dep.debian.net/deps/dep3/
--- a/gfs2/libgfs2/rgrp.c
+++ b/gfs2/libgfs2/rgrp.c
@@ -109,11 +109,17 @@ struct lgfs2_rgrp_tree *lgfs2_blk2rgrpd(struct lgfs2_sbd *sdp, uint64_t blk)
 int lgfs2_rgrp_bitbuf_alloc(lgfs2_rgrp_t rg)
 {
 	struct lgfs2_sbd *sdp = rg->rt_rgrps->rgs_sdp;
-	size_t len = rg->rt_length * sdp->sd_bsize;
+	size_t len;
 	unsigned long io_align = sdp->sd_bsize;
 	unsigned i;
 	void *bufs;
 
+	if (rg->rt_length > SIZE_MAX / sdp->sd_bsize) {
+		errno = EOVERFLOW;
+		return 1;
+	}
+	len = (size_t)rg->rt_length * sdp->sd_bsize;
+
 	if (rg->rt_rgrps->rgs_align > 0) {
 		len = ROUND_UP(len, rg->rt_rgrps->rgs_align * sdp->sd_bsize);
 		io_align = rg->rt_rgrps->rgs_align_off * sdp->sd_bsize;
@@ -190,10 +196,14 @@ void lgfs2_rgrp_crc_set(char *buf)
  */
 uint64_t lgfs2_rgrp_read(struct lgfs2_sbd *sdp, struct lgfs2_rgrp_tree *rgd)
 {
-	unsigned length = rgd->rt_length * sdp->sd_bsize;
+	size_t length;
 	off_t offset = rgd->rt_addr * sdp->sd_bsize;
 	char *buf;
 
+	if (rgd->rt_length > SIZE_MAX / sdp->sd_bsize)
+		return -1;
+	length = (size_t)rgd->rt_length * sdp->sd_bsize;
+
 	if (length == 0 || lgfs2_check_range(sdp, rgd->rt_addr))
 		return -1;
 
@@ -684,7 +694,7 @@ int lgfs2_rgrp_write(int fd, const lgfs2_rgrp_t rg)
 		mh->mh_format = cpu_to_be32(GFS2_FORMAT_RB);
 	}
 
-	len = sdp->sd_bsize * rg->rt_length;
+	len = (size_t)sdp->sd_bsize * rg->rt_length;
 	if (rg->rt_rgrps->rgs_align > 0)
 		len = ROUND_UP(len, rg->rt_rgrps->rgs_align * sdp->sd_bsize);
 
