In the Linux kernel, the following vulnerability has been resolved:ext4: ignore xattrs past endOnce inside 'ext4_xattr_inode_dec_ref_all' we shouldignore xattrs entries past the 'end' entry.This fixes the following KASAN reported issue:==================================================================BUG: KASAN: slab-use-after-free in ext4_xattr_inode_dec_ref_all+0xb8c/0xe90Read of size 4 at addr ffff888012c120c4 by task repro/2065CPU: 1 UID: 0 PID: 2065 Comm: repro Not tainted 6.13.0-rc2+ #11Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014Call Trace:
No PoCs from references.
- https://github.com/w4zu/Debian_security