Executive brief
A vulnerability exists in the Linux kernel's Squashfs file system driver, which is commonly used in embedded systems and read-only Linux distributions. A specially crafted or corrupted disk image can cause the system to read uninitialized memory, potentially leading to system instability or unauthorized access to sensitive information. This issue primarily affects systems where an attacker can mount a malicious file system or provide a corrupted disk image.
Technical details
A vulnerability in the Squashfs driver's inode handling logic allows for an uninitialized memory read. When `squashfs_read_inode()` reads a symbolic link from disk, it may assign a large, corrupted value to `inode->i_size`. When `squashfs_symlink_read_folio()` later processes this value, it is assigned to a signed integer, causing an overflow and resulting in a negative length. This causes the loop responsible for filling the page contents to be skipped entirely, leaving the page uninitialized. An attacker with the ability to mount a crafted Squashfs image could exploit this to leak kernel memory or cause a kernel panic. The fix introduces a sanity check to ensure the symbolic link size does not exceed `PAGE_SIZE`.
Affected products
- Linux Linux Kernel up to 4.19.322, 4.20 to 5.4.284, 5.5 to 5.10.226, 5.11 to 5.15.167, 5.16 to 6.1.110, 6.2 to 6.6.51, 6.7 to 6.10.10
Timeline
- 2024-08-12: other: Patch authored
- 2024-09-18: disclosed: CVE published
- 2024-09-12: patched: Patch committed to stable tree
References
- https://git.kernel.org/stable/c/087f25b2d36adae19951114ffcbb7106ed405ebb
- https://git.kernel.org/stable/c/1b9451ba6f21478a75288ea3e3fca4be35e2a438
- https://git.kernel.org/stable/c/5c8906de98d0d7ad42ff3edf2cb6cd7e0ea658c4
- https://git.kernel.org/stable/c/810ee43d9cd245d138a2733d87a24858a23f577d
- https://git.kernel.org/stable/c/c3af7e460a526007e4bed1ce3623274a1a6afe5e
- https://git.kernel.org/stable/c/ef4e249971eb77ec33d74c5c3de1e2576faf6c90
- https://git.kernel.org/stable/c/f82cb7f24032ed023fc67d26ea9bf322d8431a90