An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (out-of-bounds memory access and BUG) can occur for a modified f2fs filesystem image in which an inline inode contains an invalid reserved blkaddr.
https://www.debian.org/security/2018/dsa-4308
https://usn.ubuntu.com/4118-1/
https://usn.ubuntu.com/4094-1/
https://usn.ubuntu.com/3932-2/
https://usn.ubuntu.com/3932-1/
https://sourceforge.net/p/linux-f2fs/mailman/message/36356878/
https://seclists.org/bugtraq/2019/Jan/52
https://seclists.org/bugtraq/2018/Oct/4
https://lists.debian.org/debian-lts-announce/2018/10/msg00003.html
https://bugzilla.kernel.org/show_bug.cgi?id=200179
http://www.securityfocus.com/bid/104680
http://lists.opensuse.org/opensuse-security-announce/2018-10/msg00033.html