Description: ext4: out-of-bounds memcpy via non-inline system.data xattr References: https://bugs.chromium.org/p/project-zero/issues/detail?id=1580 https://git.kernel.org/pub/scm/linux/kernel/git/tytso/ext4.git/commit/?h=dev&id=117166efb1ee8f13c38f9e96b258f16d4923f888 Notes: carnil> fixed in ext4.git via 117166efb1ee8f13c38f9e96b258f16d4923f888 carnil> Might be needed to add as well the followup commit carnil> eb9b5f01c33adebc31cbc236c02695f605b0e417 carnil> which relates to the fix for CVE-2018-11412. Bugs: https://bugzilla.kernel.org/show_bug.cgi?id=199803 upstream: released (4.18-rc1) [117166efb1ee8f13c38f9e96b258f16d4923f888] 4.9-upstream-stable: N/A "Vulnerable code introduced in 4.13-rc1" 3.16-upstream-stable: N/A "Vulnerable code introduced in 4.13-rc1" 3.2-upstream-stable: N/A "Vulnerable code introduced in 4.13-rc1" sid: released (4.17.3-1) 4.9-stretch-security: N/A "Vulnerable code introduced later" 3.16-jessie-security: N/A "Vulnerable code introduced later" 3.2-wheezy-security: N/A "Vulnerable code introduced later"