Executive brief
A vulnerability was identified in the Linux kernel's bcache component, which is used for caching data on faster drives to speed up slower storage. An issue with how the system handles internal data structures could allow a local user to cause a system crash or instability. This primarily impacts the availability of the system rather than the confidentiality of user data.
Technical details
A vulnerability exists in the Linux kernel's bcache driver due to variable length array (VLA) abuse in the btree_iter structure. The btree_iter structure was previously defined with a fixed-length array (MAX_BSETS), but it is frequently used with dynamic sizes from a mempool based on the specific cache set. This mismatch resulted in out-of-bounds indexing for dynamically-sized iterators, detectable by UBSAN. An attacker with local access could potentially exploit this to cause a kernel panic or denial of service. The fix involves refactoring btree_iter to use a flexible array member and introducing btree_iter_stack for fixed-size stack allocations.
Affected products
- Linux Linux Kernel 5.10 to 5.10.221, 5.15 to 5.15.162, 6.1 to 6.1.94, 6.6 to 6.6.34, 6.9 to 6.9.5
Timeline
- 2024-07-05: disclosed
- 2024-07-05: advisory
References
- https://git.kernel.org/stable/c/0c31344e22dd8d6b1394c6e4c41d639015bdc671
- https://git.kernel.org/stable/c/2c3d7b03b658dc8bfa6112b194b67b92a87e081b
- https://git.kernel.org/stable/c/3a861560ccb35f2a4f0a4b8207fa7c2a35fc7f31
- https://git.kernel.org/stable/c/5a1922adc5798b7ec894cd3f197afb6f9591b023
- https://git.kernel.org/stable/c/6479b9f41583b013041943c4602e1ad61cec8148
- https://git.kernel.org/stable/c/934e1e4331859183a861f396d7dfaf33cb5afb02
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html