Description
In the Linux kernel, the following vulnerability has been resolved: jfs: nlink overflow in jfs_rename If nlink is maximal for a directory (-1) and inside that directory you perform a rename for some child directory (not moving from the parent), then the nlink of the first directory is first incremented and later decremented. Normally this is fine, but when nlink = -1 this causes a wrap around to 0, and then drop_nlink issues a warning. After applying the patch syzbot no longer issues any warnings. I also ran some basic fs tests to look for any regressions.
Product status
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 2108829a59f081e822fdab8c2cd7131deb8aa8a1
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before b4330a0d0947fbdc9d445cbbeabd8cc910a8c9ca
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before a3d66089e50a6e0142f8884471f74292102ea9aa
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before f70fcbc2ac7c24f087a2c895c5753aa730b1e479
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 5d77c36cd4b698649f5c30c5f6c084f4f61d1880
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before fe136426e30ca6debcf916fd6a141555ed9fde74
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 93c325746ae59709b4f9bad4e3e4761c8d566c70
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 9218dc26fd922b09858ecd3666ed57dfd8098da8
2.6.12
Any version before 2.6.12
5.10.252 (semver)
5.15.202 (semver)
6.1.165 (semver)
6.6.128 (semver)
6.12.75 (semver)
6.18.16 (semver)
6.19.6 (semver)
7.0 (original_commit_for_fix)
References
git.kernel.org/...c/2108829a59f081e822fdab8c2cd7131deb8aa8a1
git.kernel.org/...c/b4330a0d0947fbdc9d445cbbeabd8cc910a8c9ca
git.kernel.org/...c/a3d66089e50a6e0142f8884471f74292102ea9aa
git.kernel.org/...c/f70fcbc2ac7c24f087a2c895c5753aa730b1e479
git.kernel.org/...c/5d77c36cd4b698649f5c30c5f6c084f4f61d1880
git.kernel.org/...c/fe136426e30ca6debcf916fd6a141555ed9fde74
git.kernel.org/...c/93c325746ae59709b4f9bad4e3e4761c8d566c70
git.kernel.org/...c/9218dc26fd922b09858ecd3666ed57dfd8098da8