In the Linux kernel, the following vulnerability has been resolved:f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode()syzbot reports a kernel bug as below:F2FS-fs (loop0): Mounted with checkpoint version = 48b305e4==================================================================BUG: KASAN: slab-out-of-bounds in f2fs_test_bit fs/f2fs/f2fs.h:2933 [inline]BUG: KASAN: slab-out-of-bounds in current_nat_addr fs/f2fs/node.h:213 [inline]BUG: KASAN: slab-out-of-bounds in f2fs_get_node_info+0xece/0x1200 fs/f2fs/node.c:600Read of size 1 at addr ffff88807a58c76c by task syz-executor280/5076CPU: 1 PID: 5076 Comm: syz-executor280 Not tainted 6.9.0-rc5-syzkaller #0Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024Call Trace:
No PoCs from references.
- https://github.com/fkie-cad/nvd-json-data-feeds