Executive brief
A vulnerability in the Linux kernel's NVMe storage driver could allow a local user to cause a system crash. The issue occurs when the system attempts to process storage requests incorrectly, leading to a kernel panic. This primarily impacts system availability, potentially causing data loss or service interruptions on affected machines.
Technical details
A vulnerability exists in the nvme-pci driver within the Linux kernel due to a missing condition check in the error handling path. Specifically, nvme_unmap_data() was being called without verifying if the request actually contained physical segments, leading to a potential NULL pointer dereference if nvme_map_data() was never originally invoked. An attacker with local access could potentially trigger this condition to cause a kernel panic and denial of service. The fix introduces a check using blk_rq_nr_phys_segments(req) before calling nvme_unmap_data() to ensure symmetry with the mapping logic. Patches have been released for multiple stable kernel branches including 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.10.y.
Affected products
- Linux Linux Kernel 5.2 to 5.4.282, 5.5 to 5.10.224, 5.11 to 5.15.165, 5.16 to 6.1.103, 6.2 to 6.6.44, 6.7 to 6.10.3
Timeline
- 2024-08-17: disclosed
- 2024-08-17: advisory
- 2024-08-03: patched: Initial patches applied to stable branches.
References
- https://git.kernel.org/stable/c/3f8ec1d6b0ebd8268307d52be8301973fa5a01ec
- https://git.kernel.org/stable/c/70100fe721840bf6d8e5abd25b8bffe4d2e049b7
- https://git.kernel.org/stable/c/77848b379e9f85a08048a2c8b3b4a7e8396f5f83
- https://git.kernel.org/stable/c/7cc1f4cd90a00b6191cb8cda2d1302fdce59361c
- https://git.kernel.org/stable/c/be23ae63080e0bf9e246ab20207200bca6585eba
- https://git.kernel.org/stable/c/c31fad1470389666ac7169fe43aa65bf5b7e2cfd
- https://git.kernel.org/stable/c/d135c3352f7c947a922da93c8e763ee6bc208b64