Junglewise Threat Intelligence

CVE-2024-43858: Linux Kernel JFS array-index-out-of-bounds in diFree

CVE-2024-43858 · Severity: high · CVSS 7.8 · Published 2024-08-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's JFS file system component. This flaw could allow a local user to cause a system crash or potentially access restricted memory by triggering an out-of-bounds error during file operations. This impacts the stability and security of systems using the JFS file system.

Technical details

An improper validation of array index (CWE-129) exists in the JFS (Journaled File System) implementation within the Linux kernel, specifically in the diFree and diRead functions in fs/jfs/jfs_imap.c. The vulnerability is triggered when the code calculates an Allocation Group (AG) index from a block number (BLKTOAG) without verifying if the resulting index is within the bounds of the MAXAG array. A local attacker with low privileges can exploit this by providing a specially crafted file system image or triggering specific file operations that result in an out-of-bounds access. This can lead to a kernel oops, denial of service, or potentially local privilege escalation. Patches have been released across multiple stable kernel branches (4.19.y, 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.10.y).

Affected products

  • Linux Linux Kernel 2.6.12 to 4.19.319, 4.20 to 5.4.281, 5.5 to 5.10.223, 5.11 to 5.15.164, 5.16 to 6.1.102, 6.2 to 6.6.43, 6.7 to 6.10.2

Timeline

  • 2024-08-17: disclosed
  • 2024-08-17: advisory
  • 2024-08-19: patched

References

Related threats