{"id":"DEBIAN-CVE-2023-52604","details":"In the Linux kernel, the following vulnerability has been resolved:  FS:JFS:UBSAN:array-index-out-of-bounds in dbAdjTree  Syzkaller reported the following issue:  UBSAN: array-index-out-of-bounds in fs/jfs/jfs_dmap.c:2867:6 index 196694 is out of range for type 's8[1365]' (aka 'signed char[1365]') CPU: 1 PID: 109 Comm: jfsCommit Not tainted 6.6.0-rc3-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/04/2023 Call Trace:  \u003cTASK\u003e  __dump_stack lib/dump_stack.c:88 [inline]  dump_stack_lvl+0x1e7/0x2d0 lib/dump_stack.c:106  ubsan_epilogue lib/ubsan.c:217 [inline]  __ubsan_handle_out_of_bounds+0x11c/0x150 lib/ubsan.c:348  dbAdjTree+0x474/0x4f0 fs/jfs/jfs_dmap.c:2867  dbJoin+0x210/0x2d0 fs/jfs/jfs_dmap.c:2834  dbFreeBits+0x4eb/0xda0 fs/jfs/jfs_dmap.c:2331  dbFreeDmap fs/jfs/jfs_dmap.c:2080 [inline]  dbFree+0x343/0x650 fs/jfs/jfs_dmap.c:402  txFreeMap+0x798/0xd50 fs/jfs/jfs_txnmgr.c:2534  txUpdateMap+0x342/0x9e0  txLazyCommit fs/jfs/jfs_txnmgr.c:2664 [inline]  jfs_lazycommit+0x47a/0xb70 fs/jfs/jfs_txnmgr.c:2732  kthread+0x2d3/0x370 kernel/kthread.c:388  ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:147  ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:304  \u003c/TASK\u003e ================================================================================ Kernel panic - not syncing: UBSAN: panic_on_warn set ... CPU: 1 PID: 109 Comm: jfsCommit Not tainted 6.6.0-rc3-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/04/2023 Call Trace:  \u003cTASK\u003e  __dump_stack lib/dump_stack.c:88 [inline]  dump_stack_lvl+0x1e7/0x2d0 lib/dump_stack.c:106  panic+0x30f/0x770 kernel/panic.c:340  check_panic_on_warn+0x82/0xa0 kernel/panic.c:236  ubsan_epilogue lib/ubsan.c:223 [inline]  __ubsan_handle_out_of_bounds+0x13c/0x150 lib/ubsan.c:348  dbAdjTree+0x474/0x4f0 fs/jfs/jfs_dmap.c:2867  dbJoin+0x210/0x2d0 fs/jfs/jfs_dmap.c:2834  dbFreeBits+0x4eb/0xda0 fs/jfs/jfs_dmap.c:2331  dbFreeDmap fs/jfs/jfs_dmap.c:2080 [inline]  dbFree+0x343/0x650 fs/jfs/jfs_dmap.c:402  txFreeMap+0x798/0xd50 fs/jfs/jfs_txnmgr.c:2534  txUpdateMap+0x342/0x9e0  txLazyCommit fs/jfs/jfs_txnmgr.c:2664 [inline]  jfs_lazycommit+0x47a/0xb70 fs/jfs/jfs_txnmgr.c:2732  kthread+0x2d3/0x370 kernel/kthread.c:388  ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:147  ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:304  \u003c/TASK\u003e Kernel Offset: disabled Rebooting in 86400 seconds..  The issue is caused when the value of lp becomes greater than CTLTREESIZE which is the max size of stree. Adding a simple check solves this issue.  Dave: As the function returns a void, good error handling would require a more intrusive code reorganization, so I modified Osama's patch at use WARN_ON_ONCE for lack of a cleaner option.  The patch is tested via syzbot.","modified":"2026-09-15T09:02:48.285721466Z","published":"2024-03-06T07:15:11.347Z","upstream":["CVE-2023-52604"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-52604"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.82-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52604.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52604.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52604.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}