Executive brief
A vulnerability was identified in the Linux kernel's JFS file system component. This flaw could allow a local user to cause a system crash or potentially access restricted memory by triggering an out-of-bounds error during file operations. This impacts the stability and security of systems using the JFS file system.
Technical details
An improper validation of array index (CWE-129) exists in the JFS (Journaled File System) implementation within the Linux kernel, specifically in the diFree and diRead functions in fs/jfs/jfs_imap.c. The vulnerability is triggered when the code calculates an Allocation Group (AG) index from a block number (BLKTOAG) without verifying if the resulting index is within the bounds of the MAXAG array. A local attacker with low privileges can exploit this by providing a specially crafted file system image or triggering specific file operations that result in an out-of-bounds access. This can lead to a kernel oops, denial of service, or potentially local privilege escalation. Patches have been released across multiple stable kernel branches (4.19.y, 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.10.y).
Affected products
- Linux Linux Kernel 2.6.12 to 4.19.319, 4.20 to 5.4.281, 5.5 to 5.10.223, 5.11 to 5.15.164, 5.16 to 6.1.102, 6.2 to 6.6.43, 6.7 to 6.10.2
Timeline
- 2024-08-17: disclosed
- 2024-08-17: advisory
- 2024-08-19: patched
References
- https://git.kernel.org/stable/c/538a27c8048f081a5ddd286f886eb986fbbc7f80
- https://git.kernel.org/stable/c/55b732c8b09b41148eaab2fa8e31b0af47671e00
- https://git.kernel.org/stable/c/63f7fdf733add82f126ea00e2e48f6eba15ac4b9
- https://git.kernel.org/stable/c/6aa6892a90a5a7fabffe5692ab9f06a7a46c6e42
- https://git.kernel.org/stable/c/8d8f9a477de0d7962342eedf2a599215b7c63d28
- https://git.kernel.org/stable/c/9b3a4345957f5372041bc4f59de322f62653e862
- https://git.kernel.org/stable/c/f73f969b2eb39ad8056f6c7f3a295fa2f85e313a