CVE-2024-42305: ext4: check dot and dotdot of dx_root before making dir indexed
In the Linux kernel, the following vulnerability has been resolved:
ext4: check dot and dotdot of dxroot before making dir indexed
Syzbot reports a issue as follows: ============================================ BUG: unable to handle page fault for address: ffffed11022e24fe PGD 23ffee067 P4D 23ffee067 PUD 0 Oops: Oops: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 0 PID: 5079 Comm: syz-executor306 Not tainted 6.10.0-rc5-g55027e689933 #0 Call Trace: <TASK> makeindexeddir+0xdaf/0x13c0 fs/ext4/namei.c:2341 ext4addentry+0x222a/0x25d0 fs/ext4/namei.c:2451 ext4rename fs/ext4/namei.c:3936 [inline] ext4rename2+0x26e5/0x4370 fs/ext4/namei.c:4214 [...] ============================================
The immediate cause of this problem is that there is only one valid dentry for the block to be split during dosplit, so split==0 results in out of bounds accesses to the map triggering the issue.
dosplit unsigned split dxmakemap count = 1 split = count/2 = 0; continued = hash2 == map[split - 1].hash; ---> map[4294967295]
The maximum length of a filename is 255 and the minimum block size is 1024, so it is always guaranteed that the number of entries is greater than or equal to 2 when dosplit() is called.
But syzbot's crafted image has no dot and dotdot in dir, and the dentry distribution in dirblock is as follows:
bus dentry1 hole dentry2 free |xx--|xx-------------|...............|xx-------------|...............| 0 12 (8+248)=256 268 256 524 (8+256)=264 788 236 1024
So when renaming dentry1 increases its namelen length by 1, neither hole nor free is sufficient to hold the new dentry, and makeindexeddir() is called.
In makeindexeddir() it is assumed that the first two entries of the dirblock must be dot and dotdot, so bus and dentry1 are left in dxroot because they are treated as dot and dotdot, and only dentry2 is moved to the new leaf block. That's why count is equal to 1.
Therefore add the ext4checkdxroot() helper function to add more sanity checks to dot and dotdot before starting the conversion to avoid the above issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42305?
CVE-2024-42305 has a severity rating that indicates a potential risk of denial of service due to a page fault in the Linux kernel's ext4 filesystem.
How do I fix CVE-2024-42305?
To fix CVE-2024-42305, update your Linux kernel to a version greater than 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1.
Which versions of Linux are affected by CVE-2024-42305?
CVE-2024-42305 affects Linux kernel versions up to and including 5.10.223-1 and certain 6.x versions prior to the patched releases.
What component of the Linux kernel does CVE-2024-42305 involve?
CVE-2024-42305 involves the ext4 filesystem, specifically related to directory indexing and handling of dot and dotdot entries in dx_root.
Is there a reliable source for information on CVE-2024-42305?
The official Linux kernel Git repository contains reliable patches and information related to CVE-2024-42305.