Executive brief
A vulnerability in the Linux kernel's GFS2 file system could allow a local user to cause a system crash. The issue stems from how the system handles corrupted directory metadata, leading to an 'undefined' mathematical operation that halts the kernel. This primarily impacts system availability and could be used to disrupt operations on servers using the Global File System 2.
Technical details
A vulnerability exists in the GFS2 file system component of the Linux kernel where the i_depth for exhash directories is not properly validated in gfs2_dinode_in(). Specifically, a corrupted directory depth of 0 can trigger an undefined bitwise shift by 32 in dir_e_read() during the calculation of the hash index. This occurs because the minimum depth for an exhash directory should be ilog2(sdp->sd_hash_ptrs), and a value of 0 is invalid. An attacker with local access could potentially exploit this by mounting a specially crafted, corrupted GFS2 image to trigger a kernel panic or undefined behavior. The fix introduces a validation check to ensure the depth is not lower than the required minimum.
Affected products
- Linux Linux kernel versions up to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-09-04: disclosed
- 2025-09-04: advisory
References
- https://git.kernel.org/stable/c/076e992752e4b24178918f748d75597c80a408d2
- https://git.kernel.org/stable/c/112bb60cd0e254a369e95aa9941a694ffeca089f
- https://git.kernel.org/stable/c/366183911b153e9b8cf758e1414e1154d7569337
- https://git.kernel.org/stable/c/53a0249d68a210c16e961b83adfa82f94ee0a53d
- https://git.kernel.org/stable/c/557c024ca7250bb65ae60f16c02074106c2f197b
- https://git.kernel.org/stable/c/9680c58675b82348ab84d387e4fa727f7587e1a0
- https://git.kernel.org/stable/c/b5f46951e62377b6e406fadc18bc3c5bdf1632a7