{
        struct page *node_page;
        nid_t nid;
-       unsigned int ofs_in_node;
+       unsigned int ofs_in_node, max_addrs;
        block_t source_blkaddr;
 
        nid = le32_to_cpu(sum->nid);
                return false;
        }
 
+       max_addrs = IS_INODE(node_page) ? DEF_ADDRS_PER_INODE :
+                                               DEF_ADDRS_PER_BLOCK;
+       if (ofs_in_node >= max_addrs) {
+               f2fs_err(sbi, "Inconsistent ofs_in_node:%u in summary, ino:%u, nid:%u, max:%u",
+                       ofs_in_node, dni->ino, dni->nid, max_addrs);
+               return false;
+       }
+
        *nofs = ofs_of_node(node_page);
        source_blkaddr = data_blkaddr(NULL, node_page, ofs_in_node);
        f2fs_put_page(node_page, 1);
 
        struct dnode_of_data tdn = *dn;
        nid_t ino, nid;
        struct inode *inode;
-       unsigned int offset;
+       unsigned int offset, ofs_in_node, max_addrs;
        block_t bidx;
        int i;
 
 got_it:
        /* Use the locked dnode page and inode */
        nid = le32_to_cpu(sum.nid);
+       ofs_in_node = le16_to_cpu(sum.ofs_in_node);
+
+       max_addrs = ADDRS_PER_PAGE(dn->node_page, dn->inode);
+       if (ofs_in_node >= max_addrs) {
+               f2fs_err(sbi, "Inconsistent ofs_in_node:%u in summary, ino:%lu, nid:%u, max:%u",
+                       ofs_in_node, dn->inode->i_ino, nid, max_addrs);
+               return -EFSCORRUPTED;
+       }
+
        if (dn->inode->i_ino == nid) {
                tdn.nid = nid;
                if (!dn->inode_page_locked)
                        lock_page(dn->inode_page);
                tdn.node_page = dn->inode_page;
-               tdn.ofs_in_node = le16_to_cpu(sum.ofs_in_node);
+               tdn.ofs_in_node = ofs_in_node;
                goto truncate_out;
        } else if (dn->nid == nid) {
-               tdn.ofs_in_node = le16_to_cpu(sum.ofs_in_node);
+               tdn.ofs_in_node = ofs_in_node;
                goto truncate_out;
        }