Executive brief
A vulnerability exists in the Linux kernel's ext4 file system component, which is responsible for managing how data is stored on disks. Under specific debugging configurations, a technical error can occur where the system tries to access memory that has already been released, potentially leading to a system crash or unauthorized data access. This issue primarily affects systems where specific developer debugging features are enabled.
Technical details
A use-after-free (UAF) vulnerability exists in fs/ext4/extents.c within the Linux kernel. In functions like ext4_split_extent() and ext4_ext_handle_unwritten_extents(), a local pointer 'path' is initialized to *ppath; however, subsequent calls to ext4_find_extent() or ext4_split_extent_at() may free or reallocate the memory pointed to by *ppath. If the code then attempts to use the stale 'path' pointer in ext4_ext_show_leaf(), a UAF occurs. This vulnerability is only reachable when the kernel is compiled with EXT_DEBUG defined. An attacker with local access could potentially exploit this to cause a denial of service (system crash) or achieve privilege escalation, though the requirement for EXT_DEBUG limits the practical impact on production systems. Patches have been released for multiple stable kernel branches.
Affected products
- Linux Linux Kernel up to (excluding) 5.10.227, 5.11 up to (excluding) 5.15.168, 5.16 up to (excluding) 6.1.113, 6.2 up to (excluding) 6.6.55, 6.7 up to (excluding) 6.10.14, 6.11 up to (excluding) 6.11.3
Timeline
- 2024-10-21: disclosed
- 2024-10-21: advisory
References
- https://git.kernel.org/stable/c/2eba3b0cc5b8de624918d21f32b5b8db59a90b39
- https://git.kernel.org/stable/c/34b2096380ba475771971a778a478661a791aa15
- https://git.kernel.org/stable/c/4999fed877bb64e3e7f9ab9996de2ca983c41928
- https://git.kernel.org/stable/c/4e2524ba2ca5f54bdbb9e5153bea00421ef653f5
- https://git.kernel.org/stable/c/8b114f2cc7dd5d36729d040b68432fbd0f0a8868
- https://git.kernel.org/stable/c/b0cb4561fc4284d04e69c8a66c8504928ab2484e
- https://git.kernel.org/stable/c/d483c7cc1796bd6a80e7b3a8fd494996260f6b67