]> git.ipfire.org Git - thirdparty/linux.git/commit
jfs: fix out-of-bounds in dbNextAG() and diAlloc()
authorJeongjun Park <aha310510@gmail.com>
Mon, 19 Aug 2024 04:05:46 +0000 (13:05 +0900)
committerDave Kleikamp <dave.kleikamp@oracle.com>
Fri, 23 Aug 2024 19:15:00 +0000 (14:15 -0500)
commite63866a475562810500ea7f784099bfe341e761a
tree2944f21a6c04e9a3ac4c856dc66e80eb3cc2a683
parentb0b2fc815e514221f01384f39fbfbff65d897e1c
jfs: fix out-of-bounds in dbNextAG() and diAlloc()

In dbNextAG() , there is no check for the case where bmp->db_numag is
greater or same than MAXAG due to a polluted image, which causes an
out-of-bounds. Therefore, a bounds check should be added in dbMount().

And in dbNextAG(), a check for the case where agpref is greater than
bmp->db_numag should be added, so an out-of-bounds exception should be
prevented.

Additionally, a check for the case where agno is greater or same than
MAXAG should be added in diAlloc() to prevent out-of-bounds.

Reported-by: Jeongjun Park <aha310510@gmail.com>
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Jeongjun Park <aha310510@gmail.com>
Signed-off-by: Dave Kleikamp <dave.kleikamp@oracle.com>
fs/jfs/jfs_dmap.c
fs/jfs/jfs_imap.c