Executive brief
A vulnerability exists in the Linux kernel's Budget Fair Queuing (BFQ) storage scheduler, which manages how data is read from and written to disks. Under certain conditions where multiple tasks share the same input/output context, the system may attempt to use memory that has already been freed. This can lead to system instability, crashes, or potentially allow an attacker to gain unauthorized control over the system.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel block layer's BFQ (Budget Fair Queuing) I/O scheduler. The root cause is a race condition in bfq_limit_depth() where the code dereferences a bfq_queue (bfqq) from a bfq_io_cq (bic) without holding the necessary bfqd->lock. When an io_context is shared across multiple tasks (e.g., using io_uring), one task may free the bfqq while another is accessing it. This was identified via KASAN reports showing a slab-use-after-free in bfqq_group. The fix involves ensuring bic_to_bfqq() calls are properly protected by the scheduler lock. Patches have been released for various stable branches including 6.6.64, 6.11.11, and 6.12.2.
Affected products
- Linux Linux Kernel 5.17 to 6.6.63, 6.7 to 6.11.10, 6.12 to 6.12.1
Timeline
- 2024-11-29: patched: Initial patch submitted by Yu Kuai
- 2024-12-27: advisory: CVE-2024-53166 published
References
- https://git.kernel.org/stable/c/01a853faaeaf3379ccf358ade582b1d28752126e
- https://git.kernel.org/stable/c/906cdbdd3b018ff69cc830173bce277a847d4fdc
- https://git.kernel.org/stable/c/ada4ca5fd5a9d5212f28164d49a4885951c979c9
- https://git.kernel.org/stable/c/dcaa738afde55085ac6056252e319479cf23cde2
- https://git.kernel.org/stable/c/e8b8344de3980709080d86c157d24e7de07d70ad
- https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html