In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause _removedirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.
{ "urgency": "not yet assigned" }