Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-45000— fs/netfs/fscache_cookie: add missing "n_accesses" check

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于fs/netfs/fscache_cookie组件存在空指针解引用漏洞。

CVSS 7.8 · High EPSS 0.23% · P14

Affected Version Matrix 10

VendorProduct Version RangeStatus
Linux Linux 12bb21a29c19aae50cfad4e2bb5c943108f34a7d< b8a50877f68efdcc0be3fcc5116e00c31b90e45b affected
12bb21a29c19aae50cfad4e2bb5c943108f34a7d< dfaa39b05a6cf34a16c525a2759ee6ab26b5fef6 affected
12bb21a29c19aae50cfad4e2bb5c943108f34a7d< 0a4d41fa14b2a0efd40e350cfe8ec6a4c998ac1d affected
12bb21a29c19aae50cfad4e2bb5c943108f34a7d< f71aa06398aabc2e3eaac25acdf3d62e0094ba70 affected
5.17 affected
< 5.17 unaffected
6.1.107≤ 6.1.* unaffected
6.6.48≤ 6.6.* unaffected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-45000

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
fs/netfs/fscache_cookie: add missing "n_accesses" check
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: fs/netfs/fscache_cookie: add missing "n_accesses" check This fixes a NULL pointer dereference bug due to a data race which looks like this: BUG: kernel NULL pointer dereference, address: 0000000000000008 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: 0000 [#1] SMP PTI CPU: 33 PID: 16573 Comm: kworker/u97:799 Not tainted 6.8.7-cm4all1-hp+ #43 Hardware name: HP ProLiant DL380 Gen9/ProLiant DL380 Gen9, BIOS P89 10/17/2018 Workqueue: events_unbound netfs_rreq_write_to_cache_work RIP: 0010:cachefiles_prepare_write+0x30/0xa0 Code: 57 41 56 45 89 ce 41 55 49 89 cd 41 54 49 89 d4 55 53 48 89 fb 48 83 ec 08 48 8b 47 08 48 83 7f 10 00 48 89 34 24 48 8b 68 20 <48> 8b 45 08 4c 8b 38 74 45 49 8b 7f 50 e8 4e a9 b0 ff 48 8b 73 10 RSP: 0018:ffffb4e78113bde0 EFLAGS: 00010286 RAX: ffff976126be6d10 RBX: ffff97615cdb8438 RCX: 0000000000020000 RDX: ffff97605e6c4c68 RSI: ffff97605e6c4c60 RDI: ffff97615cdb8438 RBP: 0000000000000000 R08: 0000000000278333 R09: 0000000000000001 R10: ffff97605e6c4600 R11: 0000000000000001 R12: ffff97605e6c4c68 R13: 0000000000020000 R14: 0000000000000001 R15: ffff976064fe2c00 FS: 0000000000000000(0000) GS:ffff9776dfd40000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000008 CR3: 000000005942c002 CR4: 00000000001706f0 Call Trace: <TASK> ? __die+0x1f/0x70 ? page_fault_oops+0x15d/0x440 ? search_module_extables+0xe/0x40 ? fixup_exception+0x22/0x2f0 ? exc_page_fault+0x5f/0x100 ? asm_exc_page_fault+0x22/0x30 ? cachefiles_prepare_write+0x30/0xa0 netfs_rreq_write_to_cache_work+0x135/0x2e0 process_one_work+0x137/0x2c0 worker_thread+0x2e9/0x400 ? __pfx_worker_thread+0x10/0x10 kthread+0xcc/0x100 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x30/0x50 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1b/0x30 </TASK> Modules linked in: CR2: 0000000000000008 ---[ end trace 0000000000000000 ]--- This happened because fscache_cookie_state_machine() was slow and was still running while another process invoked fscache_unuse_cookie(); this led to a fscache_cookie_lru_do_one() call, setting the FSCACHE_COOKIE_DO_LRU_DISCARD flag, which was picked up by fscache_cookie_state_machine(), withdrawing the cookie via cachefiles_withdraw_cookie(), clearing cookie->cache_priv. At the same time, yet another process invoked cachefiles_prepare_write(), which found a NULL pointer in this code line: struct cachefiles_object *object = cachefiles_cres_object(cres); The next line crashes, obviously: struct cachefiles_cache *cache = object->volume->cache; During cachefiles_prepare_write(), the "n_accesses" counter is non-zero (via fscache_begin_operation()). The cookie must not be withdrawn until it drops to zero. The counter is checked by fscache_cookie_state_machine() before switching to FSCACHE_COOKIE_STATE_RELINQUISHING and FSCACHE_COOKIE_STATE_WITHDRAWING (in "case FSCACHE_COOKIE_STATE_FAILED"), but not for FSCACHE_COOKIE_STATE_LRU_DISCARDING ("case FSCACHE_COOKIE_STATE_ACTIVE"). This patch adds the missing check. With a non-zero access counter, the function returns and the next fscache_end_cookie_access() call will queue another fscache_cookie_state_machine() call to handle the still-pending FSCACHE_COOKIE_DO_LRU_DISCARD.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于fs/netfs/fscache_cookie组件存在空指针解引用漏洞。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 12bb21a29c19aae50cfad4e2bb5c943108f34a7d ~ b8a50877f68efdcc0be3fcc5116e00c31b90e45b -
Linux Linux 5.17 -

II. Public POCs for CVE-2024-45000

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-45000

登录查看更多情报信息。

Patches & Fixes for CVE-2024-45000 (3)

Same Patch Batch · Linux · 2024-09-04 · 58 CVEs total

CVE-2024-44984 10.0 CRITICAL bnxt_en: Fix double DMA unmapping for XDP_REDIRECT
CVE-2024-44998 9.8 CRITICAL atm: idt77252: prevent use after free in dequeue_rx()
CVE-2024-44985 9.8 CRITICAL ipv6: prevent possible UAF in ip6_xmit()
CVE-2024-44970 9.8 CRITICAL net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink
CVE-2024-44994 8.8 HIGH iommu: Restore lost return in iommu_report_device_fault()
CVE-2024-44988 8.8 HIGH net: dsa: mv88e6xxx: Fix out-of-bound access
CVE-2024-44986 8.1 HIGH ipv6: fix possible UAF in ip6_finish_output2()
CVE-2024-44973 8.1 HIGH mm, slub: do not call do_slab_free for kfence object
CVE-2024-44978 7.8 HIGH drm/xe: Free job before xe_exec_queue_put
CVE-2024-44959 7.8 HIGH tracefs: Use generic inode RCU for synchronizing freeing
CVE-2024-44954 7.8 HIGH ALSA: line6: Fix racy access to midibuf
CVE-2024-44951 7.8 HIGH serial: sc16is7xx: fix TX fifo corruption
CVE-2024-44966 7.8 HIGH binfmt_flat: Fix corruption when not offsetting data start
CVE-2024-44967 7.8 HIGH drm/mgag200: Bind I2C lifetime to DRM device
CVE-2024-44974 7.8 HIGH mptcp: pm: avoid possible UaF when selecting endp
CVE-2024-44949 7.8 HIGH parisc: fix a possible DMA corruption
CVE-2024-44987 7.8 HIGH ipv6: prevent UAF in ip6_send_skb()
CVE-2024-44995 7.8 HIGH net: hns3: fix a deadlock problem when config TC during resetting
CVE-2024-44997 7.8 HIGH net: ethernet: mtk_wed: fix use-after-free panic in mtk_wed_setup_tc_block_cb()
CVE-2024-44992 7.5 HIGH smb/client: avoid possible NULL dereference in cifs_free_subrequest()

Showing top 20 of 58 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-45000

No comments yet


Leave a comment