Junglewise Threat Intelligence

CVE-2024-35815: Linux Kernel race condition in AIO kiocb_set_cancel_fn

CVE-2024-35815 · Severity: medium · CVSS 5.5 · Published 2024-05-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Asynchronous I/O (AIO) system, which handles multiple data transfer operations simultaneously. Under certain conditions, the system could attempt to access memory incorrectly during an I/O cancellation request. This could allow a local user to cause a system crash, leading to a denial of service.

Technical details

The vulnerability exists in fs/aio.c within the kiocb_set_cancel_fn() function. The root cause is that the function performs a struct conversion (container_of) and a subsequent pointer dereference (req->ki_ctx) before verifying if the kiocb is actually an AIO request (IOCB_AIO_RW flag). Depending on compiler optimization, the read of ki_ctx could occur before the flag check, leading to an out-of-bounds read or invalid dereference if the kiocb is not embedded within an aio_kiocb structure. A local attacker with standard user privileges can trigger this behavior to cause a kernel oops or system hang. The fix ensures the IOCB_AIO_RW flag is checked before any conversion or dereference occurs.

Affected products

  • Linux Linux Kernel 4.19.308 to 4.19.312, 5.4.270 to 5.4.274, 5.10.211 to 5.10.215, 5.15.150 to 5.15.154, 6.1.80 to 6.1.84, 6.6.19 to 6.6.24, 6.7.7 to 6.7.12, 6.8.rc6 to 6.8.rc7

Timeline

  • 2024-05-17: advisory: Initial publication of CVE-2024-35815
  • 2024-04-13: patched: Fix committed to various stable kernel branches

References

Related threats