FUSE Linux Kernel Integer Overflow: pgoff_t Arithmetic Wrap, Maple Tree OOB Write & VMA Corruption
MAX_LFS_FILESIZE only gates the superblock. A poisoned FUSE_GETATTR reply mutates i_size to UINT64_MAX at runtime. The (pos + count - 1) » PAGE_SHIFT arithmetic wraps unsigned, kworker loops become infinite, and vma_merge() degenerates into an arbitrary OOB-write on Maple Tree-backed kernels. Full mm/ subsystem analysis: filemap.c, mmap.c, XArray walk corruption primitives.