Junglewise Threat Intelligence

CVE-2024-42305: Linux Kernel ext4 out-of-bounds read in make_indexed_dir

CVE-2024-42305 · Severity: medium · CVSS 5.5 · Published 2024-08-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's ext4 file system could allow a local user to crash the system. The issue occurs when the system processes a specially crafted disk image that lacks standard directory entries. This can lead to a system failure (kernel oops) when performing common file operations like renaming files within those directories.

Technical details

An out-of-bounds read vulnerability exists in the ext4 filesystem driver within the Linux kernel. The issue is located in the `make_indexed_dir` function in `fs/ext4/namei.c`, which assumes that the first two entries of a directory block are always '.' and '..'. If a crafted filesystem image lacks these entries, the `do_split` function may be called with only one valid dentry, causing a calculation error where `split` becomes 0. This results in an out-of-bounds access at `map[split - 1]`, triggering a kernel page fault. The fix introduces `ext4_check_dx_root()` to validate the presence and format of '.' and '..' entries before proceeding with directory indexing.

Affected products

  • Linux Linux Kernel 2.6.20 to 4.19.320, 4.20 to 5.4.282, 5.5 to 5.10.224, 5.11 to 5.15.165, 5.16 to 6.1.103, 6.2 to 6.6.44, 6.7 to 6.10.3

Timeline

  • 2024-07-02: patched: Initial patch submitted by maintainers
  • 2024-08-17: disclosed: CVE-2024-42305 published
  • 2024-08-19: advisory: Stable kernel updates released

References

Related threats