Executive brief
A vulnerability in the Linux kernel's JFS file system component could allow a local user to cause a system crash or potentially access sensitive memory. This issue is triggered when the system attempts to process a specially crafted or corrupted disk image. While it requires local access or the mounting of a malicious drive, it can lead to a denial of service or unauthorized data exposure.
Technical details
An out-of-bounds read vulnerability exists in the JFS (Journaled File System) implementation within the Linux kernel. The issue stems from a lack of proper bounds checking in the dbNextAG(), dbMount(), and diAlloc() functions when handling the number of allocation groups (db_numag). An attacker can exploit this by providing a 'polluted' or maliciously crafted disk image where the db_numag value exceeds the MAXAG constant. This leads to out-of-bounds memory access when the kernel attempts to perform block or inode allocation. The vulnerability can be triggered by a local user with the ability to mount a filesystem, potentially leading to a kernel panic (DoS) or information disclosure from kernel memory. Patches have been released across various stable kernel branches to enforce strict bounds checking against MAXAG.
Affected products
- Linux Linux Kernel 2.6.12 to 5.10.227, 5.11 to 5.15.168, 5.16 to 6.1.113, 6.2 to 6.6.54, 6.7 to 6.10.13, 6.11 to 6.11.2
Timeline
- 2024-08-19: other: Vulnerability reported by Jeongjun Park
- 2024-10-21: disclosed: Initial CVE publication
- 2024-10-17: patched: Fix committed to stable kernel trees
References
- https://git.kernel.org/stable/c/0338e66cba272351ca9d7d03f3628e390e70963b
- https://git.kernel.org/stable/c/128d5cfdcf844cb690c9295a3a1c1114c21fc15a
- https://git.kernel.org/stable/c/5ad6284c8d433f8a213111c5c44ead4d9705b622
- https://git.kernel.org/stable/c/6ce8b6ab44a8b5918c0ee373d4ad19d19017931b
- https://git.kernel.org/stable/c/96855f40e152989c9e7c20c4691ace5581098acc
- https://git.kernel.org/stable/c/c1ba4b8ca799ff1d99d01f37d7ccb7d5ba5533d2
- https://git.kernel.org/stable/c/d1017d2a0f3f16dc1db5120e7ddbe7c6680425b0