Executive brief
A vulnerability exists in the Linux kernel's ext4 file system, which is widely used for data storage on Linux servers and workstations. A flaw in how the system manages memory buffers during complex file operations could allow a local user to cause a system crash or potentially gain unauthorized access to data. This issue primarily impacts the reliability and security of systems using the ext4 file system.
Technical details
A double-free vulnerability (CWE-415) exists in the ext4 file system's extent management logic, specifically within the ext4_ext_try_to_merge_up() function. The root cause is a failure to nullify a buffer head pointer (path[1].p_bh) after it has been released via brelse(). Under specific conditions involving extent splitting and memory pressure (ENOMEM), subsequent error handling paths may attempt to release the same buffer a second time. This can be triggered by a local attacker performing specific file system operations, potentially leading to a kernel panic or memory corruption. Patches have been released across multiple stable kernel branches to ensure the pointer is correctly set to NULL after the first release.
Affected products
- Linux Linux Kernel 3.7 to 4.19.323, 4.20 to 5.4.285, 5.5 to 5.10.227, 5.11 to 5.15.168, 5.16 to 6.1.113, 6.2 to 6.6.55, 6.7 to 6.10.14, 6.11 to 6.11.3
Timeline
- 2024-08-22: other: Vulnerability fix authored
- 2024-10-21: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/230ee0535d01478bad9a3037292043f39b9be10b
- https://git.kernel.org/stable/c/32bbb59e3f18facd7201bef110010bf35819b8c3
- https://git.kernel.org/stable/c/68a69cf60660c73990c1875f94a5551600b04775
- https://git.kernel.org/stable/c/7633407ca4ab8be2916ab214eb44ccebc6a50e1a
- https://git.kernel.org/stable/c/78bbc3d15b6f443acb26e94418c445bac940d414
- https://git.kernel.org/stable/c/b6c29c8f3d7cb67b505f3b2f6c242d52298d1f2e
- https://git.kernel.org/stable/c/d4574bda63906bf69660e001470bfe1a0ac524ae