Executive brief
The NTFS3 filesystem driver in the Linux kernel contains a memory leak flaw that can waste kernel memory during filesystem mounting or inode processing. An attacker with the ability to mount a specially crafted NTFS volume could trigger the leak repeatedly, potentially causing a denial of service through memory exhaustion. This affects systems that support NTFS volume mounting.
Technical details
The vulnerability is a memory leak in the ntfs_read_mft() function within fs/ntfs3/inode.c. The bug occurs when the ATTR_ROOT label sets is_root = true without consistently setting the NI_FLAG_DIR flag on the inode structure. When a subsequent ATTR_ALLOC attribute allocates memory for ni->dir.alloc_run, the cleanup function ni_clear() frees the wrong union member (ni->file.run instead of ni->dir.alloc_run) if NI_FLAG_DIR was not set, causing the memory to leak. The flaw requires parsing a malformed NTFS Master File Table (MFT) entry during filesystem mount or inode lookup. A local attacker with permissions to mount filesystems or a remote attacker providing a crafted NTFS image can trigger this leak. The fix ensures is_root and NI_FLAG_DIR are always set together by moving the is_root assignment after the NI_FLAG_DIR check.
Affected products
- Linux Linux kernel Affected versions include linux-5.x, linux-6.x, and potentially earlier versions; patched in stable branches
Timeline
- 2022-11-22: other: Vulnerability fix committed by Chen Zhongjin
- 2023-05: patched: Fix merged into stable kernel branches (commit 1bc6bb657dfb0ab3b94ef6d477ca241bf7b6ec06)
- 2023-12-24: disclosed