Executive brief
A vulnerability in the Linux kernel's UDF file system driver could allow a local user to cause a system crash or unpredictable behavior. The issue occurs when the system attempts to use a corrupted file system map, failing to properly mark it as invalid after the initial detection of corruption. This can lead to service outages or system instability if a specially crafted or damaged disk image is processed.
Technical details
A vulnerability exists in the Linux kernel UDF (Universal Disk Format) file system implementation where corrupted block bitmaps are not correctly flagged as invalid after initial detection. While the kernel detects corruption during the initial loading of a bitmap and fails that specific allocation, subsequent allocation requests may see the bitmap buffer as 'already loaded' and attempt to use the corrupted data. This root cause is a lack of state tracking for verified buffers. Attackers with local access can exploit this by mounting or accessing a corrupted UDF filesystem to trigger a denial-of-service (system crash). The fix introduces the use of the BH_verified bit or ERR_PTR flagging to ensure corrupted bitmaps are not reused.
Affected products
- Linux Linux Kernel 4.14.326 to 4.15, 4.19.295 to 4.20, 5.4.257 to 5.4.282, 5.10.195 to 5.10.224, 5.15.132 to 5.15.165, 6.1.53 to 6.1.103, 6.3 to 6.6.44, 6.7 to 6.10.3
Timeline
- 2024-08-17: disclosed
- 2024-08-17: advisory
- 2024-08-19: patched
References
- https://git.kernel.org/stable/c/2199e157a465aaf98294d3932797ecd7fce942d5
- https://git.kernel.org/stable/c/271cab2ca00652bc984e269cf1208699a1e09cdd
- https://git.kernel.org/stable/c/57053b3bcf3403b80db6f65aba284d7dfe7326af
- https://git.kernel.org/stable/c/6a43e3c210df6c5f00570f4be49a897677dbcb64
- https://git.kernel.org/stable/c/8ca170c39eca7cad6e0cfeb24e351d8f8eddcd65
- https://git.kernel.org/stable/c/a90d4471146de21745980cba51ce88e7926bcc4f
- https://git.kernel.org/stable/c/cae9e59cc41683408b70b9ab569f8654866ba914