Executive brief
A vulnerability in the Linux kernel's SMB (file sharing) client could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs when the system handles encrypted file sharing requests, specifically when creating certain types of file links. This could lead to a loss of system availability or unauthorized access to sensitive kernel memory.
Technical details
The vulnerability is a heap-based out-of-bounds (OOB) write (CWE-787) within the 'cifs' module of the Linux kernel. When encryption is enforced (via the 'seal' mount option or server policy), the client squashes compound request buffers into a single iov in 'smb2_set_next_command()'. 'SMB2_ioctl_init()' allocates a small 448-byte buffer, but if a user provides an input buffer exceeding 328 bytes (e.g., via a long symlink target), the subsequent write exceeds the allocated 'iov_base' boundary. This was demonstrated using a 1024-byte symlink path which resulted in a 4116-byte OOB write. Patches have been released for various stable kernel branches including 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.11.y.
Affected products
- Linux Linux Kernel 5.0 to 5.4.285, 5.5 to 5.10.229, 5.11 to 5.15.170, 5.16 to 6.1.115, 6.2 to 6.6.59, 6.7 to 6.11.6, 6.12-rc1 to 6.12-rc3
Timeline
- 2024-10-15: patched: Initial fix authored by Paulo Alcantara
- 2024-11-07: disclosed: CVE-2024-50151 published
References
- https://git.kernel.org/stable/c/1ab60323c5201bef25f2a3dc0ccc404d9aca77f1
- https://git.kernel.org/stable/c/2ef632bfb888d1a14f81c1703817951e0bec5531
- https://git.kernel.org/stable/c/6f0516ef1290da24b85461ed08a0938af7415e49
- https://git.kernel.org/stable/c/b209c3a0bc3ac172265c7fa8309e5d00654f2510
- https://git.kernel.org/stable/c/e07d05b7f5ad9a503d9cab0afde2ab867bb65470
- https://git.kernel.org/stable/c/ed31aba8ce93472d9e16f5cff844ae7c94e9601d
- https://git.kernel.org/stable/c/fe92ddc1c32d4474e605e3a31a4afcd0e7d765ec