Hide Forgot
A flaw was found in the NILFS2 file system implementation in the Linux kernel. If the beginning of the inode bitmap area was corrupted on disk, an inode with the same inode number as the root inode could be allocated and fail soon after. The subsequent call to nilfs_clear_inode() wrongly decremented the reference counter of struct nilfs_root, leading to a use-after-free issue. A user permitted to mount arbitrary file system images could use this flaw to cause a denial of service. https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git/commit/?id=d325dc6eb763c10f591c239550b8c7e5466a5d09 https://vuldb.com/?id.211992 https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html
Upstream patch & commit: https://lore.kernel.org/all/20221003150519.39789-1-konishi.ryusuke@gmail.com/T/#u https://github.com/torvalds/linux/commit/d325dc6eb763c10f591c239550b8c7e5466a5d09