CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's OCFS2 filesystem, specifically during the unlinking of refcounted files, which can lead to an out-of-bounds write and trigger a panic. This issue arises from improper handling of memory during the conversion of a refcount tree's root back to leaf mode, potentially causing system instability. Organizations using Linux systems with OCFS2 should prioritize this fix to prevent potential crashes and ensure filesystem integrity.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent [BUG] Unlinking a refcounted file whose refcount tree has leaf blocks triggers a fortify panic due to an out-of-bounds write. [CAUSE] When the last leaf block is removed from a refcount tree, ocfs2_remove_refcount_extent() converts the root back to leaf mode with a bulk memset on &rb->rf_records. rf_records sits in an anonymous union with rf_list. rf_list.l_tree_depth aliases rf_records.rl_count, and is 0 for a single-level tree. With rl_count equal to 0, the memset writes past the 16-byte declared size of rf_records, which the fortify checker catches. [FIX] Replace the bulk memset on &rb->rf_records with a correctly-bounded memset on rl_recs[] alone, after setting rl_count to the correct value.