Executive brief
A vulnerability exists in the Linux kernel's eCryptfs cryptographic filesystem, which is used to encrypt files and directories. Due to a calculation error when creating certain security data packets, the system may write data beyond the intended memory boundaries. This could allow a local attacker to cause a system crash or potentially gain unauthorized access to sensitive information.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in fs/ecryptfs/keystore.c within the Linux kernel. The function write_tag_66_packet() calculates a buffer size that fails to account for the 1-byte cipher code and 2-byte checksum fields. Consequently, the allocated buffer is 3 bytes too small, leading to a slab-out-of-bounds write when ecryptfs_generate_key_packet_set() is called. A local attacker with the ability to trigger eCryptfs metadata operations (e.g., creating or initializing encrypted files) can exploit this to corrupt kernel memory, potentially leading to a denial of service or local privilege escalation. The issue has been patched in various stable kernel branches including 5.10.219, 5.15.161, 6.1.93, 6.6.33, 6.8.12, and 6.9.3.
Affected products
- Linux Linux Kernel 5.5 to 5.10.218, 5.11 to 5.15.160, 5.16 to 6.1.92, 6.2 to 6.6.32, 6.7 to 6.8.11, 6.9 to 6.9.2
Timeline
- 2024-03-17: other: Vulnerability fix authored
- 2024-06-12: patched: Fix committed to stable kernel trees
- 2024-06-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0d0f8ba042af16519f1ef7dd10463a33b21b677c
- https://git.kernel.org/stable/c/12db25a54ce6bb22b0af28010fff53ef9cb3fe93
- https://git.kernel.org/stable/c/1c125b9287e58f364d82174efb167414b92b11f1
- https://git.kernel.org/stable/c/235b85981051cd68fc215fd32a81c6f116bfc4df
- https://git.kernel.org/stable/c/2ed750b7ae1b5dc72896d7dd114c419afd3d1910
- https://git.kernel.org/stable/c/85a6a1aff08ec9f5b929d345d066e2830e8818e5
- https://git.kernel.org/stable/c/a20f09452e2f58f761d11ad7b96b5c894c91030e