Executive brief
A vulnerability was identified in the Linux kernel's storage management system (BFQ I/O scheduler). This flaw could allow a local user to cause a system crash or potentially corrupt memory by triggering a specific sequence of data storage requests. This affects the stability and reliability of servers and workstations running impacted versions of Linux.
Technical details
A use-after-free (UAF) vulnerability exists in the Budget Fair Queuing (BFQ) I/O scheduler within the Linux kernel. The issue occurs during the handling of 'bfqq' (BFQ queue) merge chains. When multiple processes have their I/O queues merged (e.g., Process 1 merged to Process 2, which is then merged to Process 3), the kernel incorrectly tracks the ownership of the intermediate queue. Specifically, the 'bfqq->bic' pointer may be set to a 'bic' (BFQ I/O context) that is no longer valid or is incorrectly associated, leading to a slab-use-after-free during queue cleanup or further merge operations. This was identified via KASAN reports in functions like 'bfq_do_early_stable_merge'. The fix involves validating if a queue is part of a merge chain before assigning ownership.
Affected products
- Linux Linux Kernel 6.6.0-07439-gba2303cacfda
Timeline
- 2024-09-03: patched: Fix committed to mainline kernel by Jens Axboe.
- 2024-10-21: advisory: CVE-2024-47706 published.
References
- https://git.kernel.org/stable/c/18ad4df091dd5d067d2faa8fce1180b79f7041a7
- https://git.kernel.org/stable/c/6d130db286ad0ea392c96ebb2551acf0d7308048
- https://git.kernel.org/stable/c/7faed2896d78e48ec96229e73b30b0af6c00a9aa
- https://git.kernel.org/stable/c/880692ee233ba63808182705b3333403413b58f5
- https://git.kernel.org/stable/c/8aa9de02a4be2e7006e636816ce19b0d667ceaa3
- https://git.kernel.org/stable/c/a9bdd5b36887d2bacb8bc777fd18317c99fc2587
- https://git.kernel.org/stable/c/bc2140534b2aae752e4f7cb4489642dbb5ec4777