An issue was discovered in the Linux kernel through 4.17.10. There is a buffer overflow in truncateinlineinode() in fs/f2fs/inline.c when umounting an f2fs image, because a length value may be negative.
{ "urgency": "not yet assigned" }