Junglewise Threat Intelligence

CVE-2024-35807: Linux Kernel ext4 data corruption during online resize

CVE-2024-35807 · Severity: medium · CVSS 5.5 · Published 2024-05-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's ext4 file system can lead to data corruption when resizing large storage volumes while they are online. This issue primarily affects very large file systems (typically over 16 TiB) or specific configurations where the 'resize_inode' feature is disabled. An exploit could result in permanent data loss or system instability by corrupting file system metadata during routine maintenance operations.

Technical details

A flaw in the ext4 online resizing logic (specifically within ext4_flex_group_add) fails to correctly identify when a new block group is already part of a meta block group (meta_bg). When resizing across certain boundaries (e.g., 8 GiB or 16 TiB depending on configuration), the kernel may incorrectly update backup block group descriptors, leading to physical block corruption. This occurs when 'resize_inode' is disabled, which is the default for file systems larger than 16 TiB with 4k blocks. The fix introduces a check to verify if the group being added is already part of the meta block group before updating descriptors. Patching is available across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 3.7 to 4.19.312, 4.20 to 5.4.274, 5.5 to 5.10.215, 5.11 to 5.15.154, 5.16 to 6.1.84, 6.2 to 6.6.24, 6.7 to 6.7.12, 6.8 to 6.8.3

Timeline

  • 2024-02-15: other: Vulnerability reported and fix authored
  • 2024-05-17: advisory: CVE published by NVD

References

Related threats