Executive brief
A vulnerability exists in the JFS file system component of the Linux kernel. A local user could potentially trigger a system crash or instability by exploiting an out-of-bounds memory access during specific file system operations. This primarily impacts the availability of the system.
Technical details
An out-of-bounds access vulnerability was identified in the JFS (Journaled File System) component of the Linux kernel, specifically within the dbSplit function. The root cause is a missing sanity check where the dmt_leafidx value could exceed the number of leaves per dmap tree. This was reported by syzbot and affects both control pages and leaf pages. An attacker with local user privileges can trigger this condition via crafted file system operations, leading to a kernel panic or memory corruption. The fix introduces a check in dbFindLeaf to ensure dmt_leafidx does not exceed max_idx (LPERCTL or LPERDMAP). Patches have been backported to multiple stable kernel branches.
Affected products
- Linux Linux Kernel up to (excluding) 5.10.227, 5.11 to (excluding) 5.15.168, 5.16 to (excluding) 6.1.113, 6.2 to (excluding) 6.6.55, 6.7 to (excluding) 6.10.14, 6.11 to (excluding) 6.11.3
Timeline
- 2024-10-21: disclosed
- 2024-10-21: advisory
References
- https://git.kernel.org/stable/c/058aa89b3318be3d66a103ba7c68d717561e1dc6
- https://git.kernel.org/stable/c/2451e5917c56be45d4add786e2a059dd9c2c37c4
- https://git.kernel.org/stable/c/25d2a3ff02f22e215ce53355619df10cc5faa7ab
- https://git.kernel.org/stable/c/35b91f15f44ce3c01eba058ccb864bb04743e792
- https://git.kernel.org/stable/c/4a7bf6a01fb441009a6698179a739957efd88e38
- https://git.kernel.org/stable/c/7fff9a9f866e99931cf6fa260288e55d01626582
- https://git.kernel.org/stable/c/cb0eb10558802764f07de1dc439c4609e27cb4f0