Executive brief
The Linux kernel's UDF (Universal Disk Format) file system contains a memory management bug in the file rename function. When renaming a file fails during the lookup phase, the kernel incorrectly frees the same memory buffer twice, causing a kernel warning and potential system instability. This can be exploited to trigger denial of service or potentially cause more serious kernel memory corruption.
Technical details
The vulnerability is a double-free bug in the udf_rename() function in the Linux kernel's UDF file system implementation. When udf_find_entry() returns NULL (indicating a failed file lookup), both udf_find_entry() and the calling udf_rename() function attempt to call brelse() on the same buffer_head objects (ofibh.sbh and ofibh.ebh), causing reference count imbalance. An attacker with local file system access can trigger this via a failed rename operation, leading to kernel warnings and potential memory corruption. The fix is to avoid the double brelse() call by not releasing buffers in udf_rename() when udf_find_entry() already did so.
Affected products
- Linux Linux kernel Versions with UDF file system support prior to fix
Timeline
- 2025-12-24: disclosed
- other: CVE-2022-50755 assigned