In the Linux kernel, the following vulnerability has been resolved:
fs: jfs: fix shift-out-of-bounds in dbAllocAG
Syzbot found a crash : UBSAN: shift-out-of-bounds in dbAllocAG. The
underlying bug is the missing check of bmp->db_agl2size. The field can
be greater than 64 and trigger the shift-out-of-bounds.
Fix this bug by adding a check of bmp->db_agl2size in dbMount since this
field is used in many following functions. The upper bound for this
field is L2MAXL2SIZE - L2MAXAG, thanks for the help of Dave Kleikamp.
Note that, for maintenance, I reorganized error handling code of dbMount.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-10-22 14:15
Updated : 2026-08-04 10:18
NVD link : CVE-2022-50567
Mitre link : CVE-2022-50567
CVE.ORG link : CVE-2022-50567
JSON object : View
Products Affected
No product.
CWE
No CWE.
