CVE-2022-50567

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/10/2025
Last modified:
22/10/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> fs: jfs: fix shift-out-of-bounds in dbAllocAG<br /> <br /> Syzbot found a crash : UBSAN: shift-out-of-bounds in dbAllocAG. The<br /> underlying bug is the missing check of bmp-&gt;db_agl2size. The field can<br /> be greater than 64 and trigger the shift-out-of-bounds.<br /> <br /> Fix this bug by adding a check of bmp-&gt;db_agl2size in dbMount since this<br /> field is used in many following functions. The upper bound for this<br /> field is L2MAXL2SIZE - L2MAXAG, thanks for the help of Dave Kleikamp.<br /> Note that, for maintenance, I reorganized error handling code of dbMount.

Impact