Executive brief
A vulnerability exists in the Linux kernel's pstore subsystem, which is used for storing kernel log information across reboots. Under certain conditions, the system may fail to properly handle memory allocation errors, potentially leading to a system crash. This could allow a local user to cause a denial-of-service, impacting system availability.
Technical details
A NULL pointer dereference vulnerability exists in the 'psz_kmsg_read' function within 'fs/pstore/zone.c' of the Linux kernel. The root cause is a failure to validate the return value of 'kasprintf()', which can return NULL if dynamic memory allocation fails. If the allocation fails and the resulting NULL pointer is subsequently dereferenced (e.g., by 'strlen()'), it leads to a kernel oops or crash. This is a local attack vector requiring low privileges. Patches have been released across multiple stable kernel branches (5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.8.y).
Affected products
- Linux Linux Kernel up to 5.10.215, 5.11 to 5.15.155, 5.16 to 6.1.86, 6.2 to 6.6.27, 6.7 to 6.8.6
Timeline
- 2024-01-18: other: Vulnerability fix authored
- 2024-02-22: patched: Fix committed to mainline kernel
- 2024-05-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0ff96ec22a84d80a18d7ae8ca7eb111c34ee33bb
- https://git.kernel.org/stable/c/635594cca59f9d7a8e96187600c34facb8bc0682
- https://git.kernel.org/stable/c/6f9f2e498eae7897ba5d3e33908917f68ff4abcc
- https://git.kernel.org/stable/c/98bc7e26e14fbb26a6abf97603d59532475e97f8
- https://git.kernel.org/stable/c/98e2b97acb875d65bdfc75fc408e67975cef3041
- https://git.kernel.org/stable/c/ec7256887d072f98c42cdbef4dcc80ddf84c7a70
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html