Skip to content

jfs: validate dmap parameters in dbMount() and slot chains in jfs_dtree.c - #2625

Open
vfsci-bot[bot] wants to merge 1 commit into
vfs.base.cifrom
pw/1169471/vfs.base.ci
Open

vfsci-bot[bot] wants to merge 1 commit into
vfs.base.cifrom
pw/1169471/vfs.base.ci

Conversation

@vfsci-bot

@vfsci-bot vfsci-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown

Series: https://patchwork.kernel.org/project/linux-fsdevel/list/?series=1169471
Submitter: Hui Peng
Version: 1
Patches: 1/1
Message-ID: <20260919222602.3794171-1-benquike@gmail.com>
Base: vfs.base.ci
Lore: https://lore.kernel.org/linux-fsdevel/20260919222602.3794171-1-benquike@gmail.com


Automated by ml2pr

…ee.c

Fix two filesystem corruption crashes in fs/jfs/:

1. In dbMount() (fs/jfs/jfs_dmap.c), validate db_mapsize > 0, db_numag
   <= MAXAG, db_agheight <= MAX_AGHEIGHT, and db_agwidth > 0 to prevent
   out-of-bounds array indexing on bmp->db_agfree[] and shift UB.
2. In check_dtroot(), check_dtpage(), and jfs_readdir()
   (fs/jfs/jfs_dtree.c), validate directory slot continuation indices to
   prevent cyclic or out-of-bounds slot walks.

Fixes: 1da177e ("Linux-2.6.12-rc2")
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant