Junglewise Threat Intelligence

CVE-2024-26973: Linux Kernel information leak in FAT file system filehandle encoding

CVE-2024-26973 · Severity: medium · CVSS 5.5 · Published 2024-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's FAT file system driver could allow a local user to access uninitialized memory. This occurs when the system generates specific file identifiers used for network file sharing (NFS). While the primary impact is a potential leak of small amounts of system memory information to a local user, it represents a flaw in how the kernel handles file system metadata.

Technical details

A vulnerability exists in the Linux kernel FAT file system driver within the fat_encode_fh_nostale() function in fs/fat/nfs.c. When encoding a file handle without a parent, the function only initializes the first 10 bytes of the handle. Because file handles must be multiples of 4 bytes in length, the resulting 12-byte handle contains 2 bytes of uninitialized kernel memory. A local attacker with the ability to request file handles (e.g., via name_to_handle_at) could potentially read these uninitialized bytes, leading to an information leak. The issue has been resolved by explicitly zero-initializing the remaining fields in the file handle structure.

Affected products

  • Linux Linux Kernel 3.10 to 4.19.312, 4.20 to 5.4.274, 5.5 to 5.10.215, 5.11 to 5.15.154, 5.16 to 6.1.84, 6.2 to 6.6.24, 6.7 to 6.7.12, 6.8 to 6.8.3

Timeline

  • 2024-02-05: other: Vulnerability reported by syzbot
  • 2024-04-03: patched: Fix committed to various stable kernel branches
  • 2024-05-01: advisory: CVE published

References

Related threats