]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
jfs: fix out-of-bounds in dbNextAG() and diAlloc()
authorJeongjun Park <aha310510@gmail.com>
Mon, 19 Aug 2024 04:05:46 +0000 (13:05 +0900)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 17 Oct 2024 13:10:53 +0000 (15:10 +0200)
commitead82533278502428883085a787d5a00f15e5eb9
tree303c5c1258edec56fc3b1a00b11e7c76629be479
parent16a570f07d870a285b0c0b0d1ca4dff79e8aa5ff
jfs: fix out-of-bounds in dbNextAG() and diAlloc()

[ Upstream commit e63866a475562810500ea7f784099bfe341e761a ]

In dbNextAG() , there is no check for the case where bmp->db_numag is
greater or same than MAXAG due to a polluted image, which causes an
out-of-bounds. Therefore, a bounds check should be added in dbMount().

And in dbNextAG(), a check for the case where agpref is greater than
bmp->db_numag should be added, so an out-of-bounds exception should be
prevented.

Additionally, a check for the case where agno is greater or same than
MAXAG should be added in diAlloc() to prevent out-of-bounds.

Reported-by: Jeongjun Park <aha310510@gmail.com>
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Jeongjun Park <aha310510@gmail.com>
Signed-off-by: Dave Kleikamp <dave.kleikamp@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
fs/jfs/jfs_dmap.c
fs/jfs/jfs_imap.c