Junglewise Threat Intelligence

CVE-2024-43828: Linux Kernel ext4 infinite loop in fast_commit replay

CVE-2024-43828 · Severity: medium · CVSS 5.5 · Published 2024-08-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's ext4 file system could allow a local user to cause a system hang or denial of service. When the system attempts to recover the file system using the 'fast_commit' feature, a software error can trigger an infinite loop. This prevents the system from completing the recovery process and may render the affected storage volume inaccessible.

Technical details

A vulnerability exists in the ext4 file system component of the Linux kernel where an uninitialized 'extent_status' structure can lead to an infinite loop. During a fast_commit replay, the function 'ext4_ext_determine_insert_hole()' calls 'ext4_es_find_extent_range()'. Because the latter returns immediately during replay without initializing the 'es' variable, the structure contains garbage data. This garbage data can trigger an integer overflow in subsequent logic, resulting in an infinite loop (CWE-835). The issue is fixed by ensuring the structure is unconditionally initialized. The vulnerability is reachable by local users and impacts system availability.

Affected products

  • Linux Linux Kernel 5.10 to 5.10.223, 5.11 to 5.15.164, 5.16 to 6.1.102, 6.2 to 6.6.43, 6.7 to 6.10.2

Timeline

  • 2024-08-17: disclosed
  • 2024-08-17: advisory
  • 2024-08-19: patched

References

Related threats