In the Linux kernel, the following vulnerability has been resolved:
ext4: update s_journal_inum if it changes after journal replay
When mounting a crafted ext4 image, s_journal_inum may change after journal replay, which is obviously unreasonable because we have successfully loaded and replayed the journal through the old s_journal_inum. And the new s_journal_inum bypasses some of the checks in ext4_get_journal(), which may trigger a null pointer dereference problem. So if s_journal_inum changes after the journal replay, we ignore the change, and rewrite the current journal_inum to the superblock.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 5.15.104 |
| linux / linux_kernel | 5.16 | 6.1.21 |
| linux / linux_kernel | 6.2 | 6.2.8 |