Junglewise Threat Intelligence

CVE-2024-38578: Linux Kernel out-of-bounds write in ecryptfs Tag 66 packet handling

CVE-2024-38578 · Severity: high · CVSS 7.8 · Published 2024-06-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's eCryptfs cryptographic filesystem, which is used to encrypt files and directories. Due to a calculation error when creating certain security data packets, the system may write data beyond the intended memory boundaries. This could allow a local attacker to cause a system crash or potentially gain unauthorized access to sensitive information.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in fs/ecryptfs/keystore.c within the Linux kernel. The function write_tag_66_packet() calculates a buffer size that fails to account for the 1-byte cipher code and 2-byte checksum fields. Consequently, the allocated buffer is 3 bytes too small, leading to a slab-out-of-bounds write when ecryptfs_generate_key_packet_set() is called. A local attacker with the ability to trigger eCryptfs metadata operations (e.g., creating or initializing encrypted files) can exploit this to corrupt kernel memory, potentially leading to a denial of service or local privilege escalation. The issue has been patched in various stable kernel branches including 5.10.219, 5.15.161, 6.1.93, 6.6.33, 6.8.12, and 6.9.3.

Affected products

  • Linux Linux Kernel 5.5 to 5.10.218, 5.11 to 5.15.160, 5.16 to 6.1.92, 6.2 to 6.6.32, 6.7 to 6.8.11, 6.9 to 6.9.2

Timeline

  • 2024-03-17: other: Vulnerability fix authored
  • 2024-06-12: patched: Fix committed to stable kernel trees
  • 2024-06-19: disclosed: CVE published

References

Related threats