Executive brief
A vulnerability in the Linux kernel's block I/O cost controller could lead to unpredictable system behavior or crashes. This component is responsible for managing how different processes share disk access to ensure fair performance. An exploit could allow a local user to cause a system hang or potentially access sensitive information due to memory handling errors.
Technical details
A shift-out-of-bounds vulnerability exists in block/blk-iocost.c within the iocg_kick_delay function. The root cause is an undefined behavior where the iocg->delay value is right-shifted by an exponent that can exceed the bit-width of the 64-bit type (u64), specifically when the calculated tdelta is large. This was identified by UBSAN (Undefined Behavior Sanitizer) as a shift exponent of 64 or greater. A local attacker with low privileges could potentially trigger this condition to cause a kernel panic (DoS) or other undefined side effects. The fix introduces a check to ensure the shift exponent is less than BITS_PER_LONG, defaulting the delay to zero if the limit is exceeded.
Affected products
- Linux Linux Kernel 5.10 to 5.10.217, 5.11 to 5.15.159, 5.16 to 6.1.91, 6.2 to 6.6.31, 6.7 to 6.8.10, 6.9-rc1 to 6.9-rc3
Timeline
- 2024-04-04: other: Patch authored
- 2024-05-17: patched: Patch committed to stable trees
- 2024-05-30: disclosed: CVE published
References
- https://git.kernel.org/stable/c/488dc6808cb8369685f18cee81e88e7052ac153b
- https://git.kernel.org/stable/c/62accf6c1d7b433752cb3591bba8967b7a801ad5
- https://git.kernel.org/stable/c/844fc023e9f14a4fb1de5ae1eaefafd6d69c5fa1
- https://git.kernel.org/stable/c/beaa51b36012fad5a4d3c18b88a617aea7a9b96d
- https://git.kernel.org/stable/c/ce0e99cae00e3131872936713b7f55eefd53ab86
- https://git.kernel.org/stable/c/f6add0a6f78dc6360b822ca4b6f9f2f14174c8ca
- https://lists.debian.org/debian-lts-announce/2024/06/msg00019.html