Executive brief
A vulnerability exists in the Linux kernel's sysfs file system interface, which is used to manage hardware and kernel settings. A flaw in how the system handles internal references can lead to a resource leak or a system crash (access violation) under specific error conditions. This could allow a local user to cause a denial-of-service, potentially impacting the availability of the affected system.
Technical details
A reference leak exists in fs/sysfs/file.c within the sysfs_break_active_protection() routine. When the function is called, it acquires a reference to a kobject; however, if the subsequent call to kernfs_find_and_get() fails (returning NULL), the error path fails to release this reference. Furthermore, because the companion routine sysfs_unbreak_active_protection() is not called when the node is NULL, the reference is never put, and any attempt to force the unbreak routine would result in a NULL pointer dereference of kn->parent. This local vulnerability allows an attacker to trigger a kernel reference leak or a denial-of-service. The issue has been resolved by adding an explicit kobject_put() call in the error path.
Affected products
- Linux Linux kernel 3.16.62 to 3.17, 3.18.121 to 3.19, 4.4.154 to 4.5, 4.9.125 to 4.10, 4.14.68 to 4.15, 4.18.6 to 4.19, 4.19 to 5.15.157, 5.16 to 6.1.88, 6.2 to 6.6.29, 6.7 to 6.8.8, 6.9-rc1 to 6.9-rc4
Timeline
- 2024-03-13: other: Vulnerability fix authored
- 2024-04-27: patched: Fix committed to stable branches
- 2024-05-01: disclosed: CVE published
References
- https://git.kernel.org/stable/c/43f00210cb257bcb0387e8caeb4b46375d67f30c
- https://git.kernel.org/stable/c/57baab0f376bec8f54b0fe6beb8f77a57c228063
- https://git.kernel.org/stable/c/5d43e072285e81b0b63cee7189b3357c7768a43b
- https://git.kernel.org/stable/c/84bd4c2ae9c3d0a7d3a5c032ea7efff17af17e17
- https://git.kernel.org/stable/c/a4c99b57d43bab45225ba92d574a8683f9edc8e4
- https://git.kernel.org/stable/c/a90bca2228c0646fc29a72689d308e5fe03e6d78
- https://git.kernel.org/stable/c/ac107356aabc362aaeb77463e814fc067a5d3957