Executive brief
A vulnerability in the Linux kernel's FAT file system driver could allow a local user to access uninitialized memory. This occurs when the system generates specific file identifiers used for network file sharing (NFS). While the primary impact is a potential leak of small amounts of system memory information to a local user, it represents a flaw in how the kernel handles file system metadata.
Technical details
A vulnerability exists in the Linux kernel FAT file system driver within the fat_encode_fh_nostale() function in fs/fat/nfs.c. When encoding a file handle without a parent, the function only initializes the first 10 bytes of the handle. Because file handles must be multiples of 4 bytes in length, the resulting 12-byte handle contains 2 bytes of uninitialized kernel memory. A local attacker with the ability to request file handles (e.g., via name_to_handle_at) could potentially read these uninitialized bytes, leading to an information leak. The issue has been resolved by explicitly zero-initializing the remaining fields in the file handle structure.
Affected products
- Linux Linux Kernel 3.10 to 4.19.312, 4.20 to 5.4.274, 5.5 to 5.10.215, 5.11 to 5.15.154, 5.16 to 6.1.84, 6.2 to 6.6.24, 6.7 to 6.7.12, 6.8 to 6.8.3
Timeline
- 2024-02-05: other: Vulnerability reported by syzbot
- 2024-04-03: patched: Fix committed to various stable kernel branches
- 2024-05-01: advisory: CVE published
References
- https://git.kernel.org/stable/c/03a7e3f2ba3ca25f1da1d3898709a08db14c1abb
- https://git.kernel.org/stable/c/74f852654b8b7866f15323685f1e178d3386c688
- https://git.kernel.org/stable/c/9840d1897e28f8733cc1e38f97e044f987dc0a63
- https://git.kernel.org/stable/c/a276c595c3a629170b0f052a3724f755d7c6adc6
- https://git.kernel.org/stable/c/b7fb63e807c6dadf7ecc1d43448c4f1711d7eeee
- https://git.kernel.org/stable/c/c8cc05de8e6b5612b6e9f92c385c1a064b0db375
- https://git.kernel.org/stable/c/cdd33d54e789d229d6d5007cbf3f53965ca1a5c6