Junglewise Threat Intelligence

CVE-2024-36916: Linux Kernel shift-out-of-bounds in blk-iocost

CVE-2024-36916 · Severity: high · CVSS 7.1 · Published 2024-05-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's block I/O cost controller could lead to unpredictable system behavior or crashes. This component is responsible for managing how different processes share disk access to ensure fair performance. An exploit could allow a local user to cause a system hang or potentially access sensitive information due to memory handling errors.

Technical details

A shift-out-of-bounds vulnerability exists in block/blk-iocost.c within the iocg_kick_delay function. The root cause is an undefined behavior where the iocg->delay value is right-shifted by an exponent that can exceed the bit-width of the 64-bit type (u64), specifically when the calculated tdelta is large. This was identified by UBSAN (Undefined Behavior Sanitizer) as a shift exponent of 64 or greater. A local attacker with low privileges could potentially trigger this condition to cause a kernel panic (DoS) or other undefined side effects. The fix introduces a check to ensure the shift exponent is less than BITS_PER_LONG, defaulting the delay to zero if the limit is exceeded.

Affected products

  • Linux Linux Kernel 5.10 to 5.10.217, 5.11 to 5.15.159, 5.16 to 6.1.91, 6.2 to 6.6.31, 6.7 to 6.8.10, 6.9-rc1 to 6.9-rc3

Timeline

  • 2024-04-04: other: Patch authored
  • 2024-05-17: patched: Patch committed to stable trees
  • 2024-05-30: disclosed: CVE published

References

Related threats