Junglewise Threat Intelligence

CVE-2024-47701: Linux Kernel EXT4 out-of-bounds access in inline directory lookup

CVE-2024-47701 · Severity: high · CVSS 7.8 · Published 2024-10-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's EXT4 filesystem could allow a local attacker to cause a system crash or potentially access restricted memory. The issue occurs when the system processes specifically formatted directories that use 'inline data' features. If the underlying data on the storage device is modified unexpectedly, it can trigger a memory error that disrupts normal operations.

Technical details

A use-after-free (UAF) vulnerability exists in the EXT4 filesystem's inline data handling. When looking up an entry in an inlined directory, the kernel relies on 'e_value_offs' within the system.data extended attribute (xattr). If this value is modified on the block device underneath the filesystem, it can lead to an out-of-bounds access in 'ext4_search_dir'. The root cause is a lack of xattr validity checking after reading the inode location. The fix introduces a call to 'ext4_xattr_ibody_find' immediately after 'ext4_get_inode_loc' to ensure the integrity of the xattrs before they are processed. This vulnerability is reachable via local system calls such as 'symlinkat' or 'lookup'.

Affected products

  • Linux Linux Kernel 3.8 to 5.10.226, 5.11 to 5.15.167, 5.16 to 6.1.112, 6.2 to 6.6.53, 6.7 to 6.10.12, 6.11-rc1 to 6.11-rc4

Timeline

  • 2024-08-21: patched: Initial fix authored by Thadeu Lima de Souza Cascardo
  • 2024-10-21: advisory: NVD publication date

References

Related threats