Executive brief
A vulnerability in the Linux kernel's Btrfs file system could allow a local user to access sensitive information from the system's memory. The issue occurs when the system provides file-related data to a user without first clearing out old data stored in that memory space. This could lead to the exposure of private kernel information to unauthorized local users.
Technical details
An information leak vulnerability exists in the Linux kernel's Btrfs implementation within the btrfs_ioctl_logical_to_ino() function. The root cause is the use of kvmalloc() in init_data_container() to allocate a 'struct btrfs_data_container', which does not zero-initialize the allocated memory before it is copied back to user-space via copy_to_user(). A local attacker with sufficient privileges to call this ioctl can read uninitialized kernel memory, potentially revealing sensitive data. The vulnerability has been addressed by replacing kvmalloc() with kvzalloc() to ensure memory is zeroed upon allocation. Fixes are available in various stable kernel branches including 4.19.313, 5.4.275, 5.10.216, 5.15.158, 6.1.90, 6.6.30, and 6.8.9.
Affected products
- Linux Linux Kernel 4.14 to 6.8.9
Timeline
- 2024-04-17: patched: Initial patch authored
- 2024-05-17: disclosed: CVE published
References
- https://git.kernel.org/stable/c/2f7ef5bb4a2f3e481ef05fab946edb97c84f67cf
- https://git.kernel.org/stable/c/30189e54ba80e3209d34cfeea87b848f6ae025e6
- https://git.kernel.org/stable/c/3a63cee1a5e14a3e52c19142c61dd5fcb524f6dc
- https://git.kernel.org/stable/c/689efe22e9b5b7d9d523119a9a5c3c17107a0772
- https://git.kernel.org/stable/c/73db209dcd4ae026021234d40cfcb2fb5b564b86
- https://git.kernel.org/stable/c/8bdbcfaf3eac42f98e5486b3d7e130fa287811f6
- https://git.kernel.org/stable/c/e58047553a4e859dafc8d1d901e1de77c9dd922d