Executive brief
A flaw in the Linux kernel's ext4 filesystem can cause a double unlock of a directory inode when moving or renaming a directory. This can lead to kernel lock corruption, causing system crashes, data corruption, or a denial of service on systems using ext4-based storage.
Technical details
The vulnerability is a double-unlock bug in the ext4_rename function in fs/ext4/namei.c. When renaming a directory, if ext4_rename_dir_prepare() fails, the code path incorrectly calls inode_unlock() on the old directory inode before jumping to end_rename, where the inode is unlocked a second time. This is a concurrency/locking error that can corrupt kernel synchronization primitives. The bug affects the kernel's directory rename operation, which is accessible locally to any process performing filesystem operations. A fix removes the redundant inode_unlock() call on the error path. Patches are available in the Linux stable kernel tree.
Affected products
- Linux Linux kernel multiple versions with ext4 filesystem support
Timeline
- 2023-03-17: disclosed
- 2023-03-22: patched