Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-44941— f2fs: fix to cover read extent cache access with lock

CVSS 7.8 · High EPSS 0.21% · P12

Affected Version Matrix 8

VendorProductVersion RangeStatus
LinuxLinux98e4da8ca301e062d79ae168c67e56f3c3de3ce4< 263df78166d3a9609b97d28c34029bd01874cbb8affected
98e4da8ca301e062d79ae168c67e56f3c3de3ce4< 323ef20b5558b9d9fd10c1224327af6f11a8177daffected
98e4da8ca301e062d79ae168c67e56f3c3de3ce4< d7409b05a64f212735f0d33f5f1602051a886eabaffected
3.8affected
< 3.8unaffected
6.6.47≤ 6.6.*unaffected
6.10.6≤ 6.10.*unaffected
6.11≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-44941

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
f2fs: fix to cover read extent cache access with lock
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to cover read extent cache access with lock syzbot reports a f2fs bug as below: BUG: KASAN: slab-use-after-free in sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46 Read of size 4 at addr ffff8880739ab220 by task syz-executor200/5097 CPU: 0 PID: 5097 Comm: syz-executor200 Not tainted 6.9.0-rc6-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114 print_address_description mm/kasan/report.c:377 [inline] print_report+0x169/0x550 mm/kasan/report.c:488 kasan_report+0x143/0x180 mm/kasan/report.c:601 sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46 do_read_inode fs/f2fs/inode.c:509 [inline] f2fs_iget+0x33e1/0x46e0 fs/f2fs/inode.c:560 f2fs_nfs_get_inode+0x74/0x100 fs/f2fs/super.c:3237 generic_fh_to_dentry+0x9f/0xf0 fs/libfs.c:1413 exportfs_decode_fh_raw+0x152/0x5f0 fs/exportfs/expfs.c:444 exportfs_decode_fh+0x3c/0x80 fs/exportfs/expfs.c:584 do_handle_to_path fs/fhandle.c:155 [inline] handle_to_path fs/fhandle.c:210 [inline] do_handle_open+0x495/0x650 fs/fhandle.c:226 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f We missed to cover sanity_check_extent_cache() w/ extent cache lock, so, below race case may happen, result in use after free issue. - f2fs_iget - do_read_inode - f2fs_init_read_extent_tree : add largest extent entry in to cache - shrink - f2fs_shrink_read_extent_tree - __shrink_extent_tree - __detach_extent_node : drop largest extent entry - sanity_check_extent_cache : access et->largest w/o lock let's refactor sanity_check_extent_cache() to avoid extent cache access and call it before f2fs_init_read_extent_tree() to fix this issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在sanity_check_extent_cache函数中未正确锁定,导致内存释放后重用问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 ~ 263df78166d3a9609b97d28c34029bd01874cbb8 -
LinuxLinux 3.8 -

II. Public POCs for CVE-2024-44941

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-44941

登录查看更多情报信息。

Other References for CVE-2024-44941 (3)

Same Patch Batch · Linux · 2024-08-26 · 39 CVEs total

CVE-2024-449427.8 HIGHf2fs: fix to do sanity check on F2FS_INLINE_DATA flag in inode during GC
CVE-2024-439107.8 HIGHbpf: add missing check_func_arg_reg_off() to prevent out-of-bounds memory accesses
CVE-2024-449347.8 HIGHnet: bridge: mcast: wait for previous gc cycles when removing port
CVE-2024-438977.8 HIGHnet: drop bad gso csum_start and offset in virtio_net_hdr
CVE-2024-438927.8 HIGHmemcg: protect concurrent access to mem_cgroup_idr
CVE-2024-438917.8 HIGHtracing: Have format file honor EVENT_FILE_FL_FREED
CVE-2024-449397.8 HIGHjfs: fix null ptr deref in dtInsertEntry
CVE-2024-438887.8 HIGHmm: list_lru: fix UAF for memory cgroup
CVE-2024-449407.5 HIGHfou: remove warn in gue_gro_receive on unsupported protocol
CVE-2024-449337.3 HIGHbnxt_en : Fix memory out-of-bounds in bnxt_fill_hw_rss_tbl()
CVE-2024-439137.0 HIGHnvme: apple: fix device reference counting
CVE-2024-44938jfs: Fix shift-out-of-bounds in dbDiscardAG
CVE-2024-44937platform/x86: intel-vbtn: Protect ACPI notify handler against recursion
CVE-2024-44936power: supply: rt5033: Bring back i2c_set_clientdata
CVE-2024-44935sctp: Fix null-ptr-deref in reuseport_add_sock().
CVE-2024-44932idpf: fix UAFs when destroying the queues
CVE-2024-44931gpio: prevent potential speculation leaks in gpio_device_get_desc()
CVE-2024-43914md/raid5: avoid BUG_ON() while continue reshape after reassembling
CVE-2024-43912wifi: nl80211: disallow setting special AP channel widths
CVE-2024-43911wifi: mac80211: fix NULL dereference at band check in starting tx ba session

Showing top 20 of 39 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-44941

No comments yet


Leave a comment