Executive brief
A vulnerability in the Linux kernel's SCSI subsystem could allow a local user to cause a system instability or resource leak. The issue occurs when certain storage devices (like USB mass storage) fail during initialization, leaving behind internal directory entries that should have been cleaned up. This can lead to kernel warnings and potential memory leaks, impacting the long-term reliability of the operating system.
Technical details
A regression in the SCSI core's procfs management causes a failure to remove the '/proc/scsi/${proc_name}' directory when a SCSI host is allocated but not successfully added (e.g., during a failed usb-storage probe). The root cause was the removal of the 'scsi_proc_hostdir_rm' call from 'scsi_host_dev_release' in a previous bug fix, which failed to account for error paths where 'scsi_add_host' is never called. An attacker or a malfunctioning device (triggered via tools like Syzkaller or USB raw gadgets) can cause a leak of the SCSI host proc structure and trigger kernel warnings in 'fs/proc/generic.c'. The fix re-introduces the removal call in 'dev_release' specifically for hosts in the 'SHOST_CREATED' state.
Affected products
- Linux Linux Kernel 5.4.238 to 5.4.274, 5.10.176 to 5.10.215, 5.15.104 to 5.15.154, 6.1.21 to 6.1.84, 6.2.8 to 6.3, 6.3.1 to 6.6.24, 6.7 to 6.7.12, 6.8 to 6.8.3
Timeline
- 2024-03-13: patched: Initial patch submitted by Guilherme G. Piccoli
- 2024-05-01: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/0053f15d50d50c9312d8ab9c11e2e405812dfcac
- https://git.kernel.org/stable/c/3678cf67ff7136db1dd3bf63c361650db5d92889
- https://git.kernel.org/stable/c/5c2386ba80e779a92ec3bb64ccadbedd88f779b1
- https://git.kernel.org/stable/c/cea234bb214b17d004dfdccce4491e6ff57c96ee
- https://git.kernel.org/stable/c/d4c34782b6d7b1e68d18d9549451b19433bd4c6c
- https://git.kernel.org/stable/c/e293c773c13b830cdc251f155df2254981abc320
- https://git.kernel.org/stable/c/f23a4d6e07570826fe95023ca1aa96a011fa9f84