Executive brief
A vulnerability was identified in the Linux kernel's Asynchronous I/O (AIO) system, which handles multiple data transfer operations simultaneously. Under certain conditions, the system could attempt to access memory incorrectly during an I/O cancellation request. This could allow a local user to cause a system crash, leading to a denial of service.
Technical details
The vulnerability exists in fs/aio.c within the kiocb_set_cancel_fn() function. The root cause is that the function performs a struct conversion (container_of) and a subsequent pointer dereference (req->ki_ctx) before verifying if the kiocb is actually an AIO request (IOCB_AIO_RW flag). Depending on compiler optimization, the read of ki_ctx could occur before the flag check, leading to an out-of-bounds read or invalid dereference if the kiocb is not embedded within an aio_kiocb structure. A local attacker with standard user privileges can trigger this behavior to cause a kernel oops or system hang. The fix ensures the IOCB_AIO_RW flag is checked before any conversion or dereference occurs.
Affected products
- Linux Linux Kernel 4.19.308 to 4.19.312, 5.4.270 to 5.4.274, 5.10.211 to 5.10.215, 5.15.150 to 5.15.154, 6.1.80 to 6.1.84, 6.6.19 to 6.6.24, 6.7.7 to 6.7.12, 6.8.rc6 to 6.8.rc7
Timeline
- 2024-05-17: advisory: Initial publication of CVE-2024-35815
- 2024-04-13: patched: Fix committed to various stable kernel branches
References
- https://git.kernel.org/stable/c/10ca82aff58434e122c7c757cf0497c335f993f3
- https://git.kernel.org/stable/c/18d5fc3c16cc317bd0e5f5dabe0660df415cadb7
- https://git.kernel.org/stable/c/396dbbc18963648e9d1a4edbb55cfe08fa374d50
- https://git.kernel.org/stable/c/5c43d0041e3a05c6c41c318b759fff16d2384596
- https://git.kernel.org/stable/c/94eb0293703ced580f05dfbe5a57da5931e9aee2
- https://git.kernel.org/stable/c/961ebd120565cb60cebe21cb634fbc456022db4a
- https://git.kernel.org/stable/c/a71cba07783abc76b547568b6452cd1dd9981410