Executive brief
A vulnerability in the Linux kernel's ext4 file system could allow a local user to crash the system. The issue occurs when the system processes a specially crafted disk image that lacks standard directory entries. This can lead to a system failure (kernel oops) when performing common file operations like renaming files within those directories.
Technical details
An out-of-bounds read vulnerability exists in the ext4 filesystem driver within the Linux kernel. The issue is located in the `make_indexed_dir` function in `fs/ext4/namei.c`, which assumes that the first two entries of a directory block are always '.' and '..'. If a crafted filesystem image lacks these entries, the `do_split` function may be called with only one valid dentry, causing a calculation error where `split` becomes 0. This results in an out-of-bounds access at `map[split - 1]`, triggering a kernel page fault. The fix introduces `ext4_check_dx_root()` to validate the presence and format of '.' and '..' entries before proceeding with directory indexing.
Affected products
- Linux Linux Kernel 2.6.20 to 4.19.320, 4.20 to 5.4.282, 5.5 to 5.10.224, 5.11 to 5.15.165, 5.16 to 6.1.103, 6.2 to 6.6.44, 6.7 to 6.10.3
Timeline
- 2024-07-02: patched: Initial patch submitted by maintainers
- 2024-08-17: disclosed: CVE-2024-42305 published
- 2024-08-19: advisory: Stable kernel updates released
References
- https://git.kernel.org/stable/c/19e13b4d7f0303186fcc891aba8d0de7c8fdbda8
- https://git.kernel.org/stable/c/42d420517072028fb0eb852c358056b7717ba5aa
- https://git.kernel.org/stable/c/50ea741def587a64e08879ce6c6a30131f7111e7
- https://git.kernel.org/stable/c/8afe06ed3be7a874b3cd82ef5f8959aca8d6429a
- https://git.kernel.org/stable/c/9d241b7a39af192d1bb422714a458982c7cc67a2
- https://git.kernel.org/stable/c/abb411ac991810c0bcbe51c2e76d2502bf611b5c
- https://git.kernel.org/stable/c/b80575ffa98b5bb3a5d4d392bfe4c2e03e9557db