CVE-2024-42305: ext4: check dot and dotdot of dx_root before making dir indexed

Published Aug 17, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ext4: check dot and dotdot of dxroot before making dir indexed

Syzbot reports a issue as follows: ============================================ BUG: unable to handle page fault for address: ffffed11022e24fe PGD 23ffee067 P4D 23ffee067 PUD 0 Oops: Oops: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 0 PID: 5079 Comm: syz-executor306 Not tainted 6.10.0-rc5-g55027e689933 #0 Call Trace: <TASK> makeindexeddir+0xdaf/0x13c0 fs/ext4/namei.c:2341 ext4addentry+0x222a/0x25d0 fs/ext4/namei.c:2451 ext4rename fs/ext4/namei.c:3936 [inline] ext4rename2+0x26e5/0x4370 fs/ext4/namei.c:4214 [...] ============================================

The immediate cause of this problem is that there is only one valid dentry for the block to be split during dosplit, so split==0 results in out of bounds accesses to the map triggering the issue.

dosplit unsigned split dxmakemap count = 1 split = count/2 = 0; continued = hash2 == map[split - 1].hash; ---> map[4294967295]

The maximum length of a filename is 255 and the minimum block size is 1024, so it is always guaranteed that the number of entries is greater than or equal to 2 when dosplit() is called.

But syzbot's crafted image has no dot and dotdot in dir, and the dentry distribution in dirblock is as follows:

bus dentry1 hole dentry2 free |xx--|xx-------------|...............|xx-------------|...............| 0 12 (8+248)=256 268 256 524 (8+256)=264 788 236 1024

So when renaming dentry1 increases its namelen length by 1, neither hole nor free is sufficient to hold the new dentry, and makeindexeddir() is called.

In makeindexeddir() it is assumed that the first two entries of the dirblock must be dot and dotdot, so bus and dentry1 are left in dxroot because they are treated as dot and dotdot, and only dentry2 is moved to the new leaf block. That's why count is equal to 1.

Therefore add the ext4checkdxroot() helper function to add more sanity checks to dot and dotdot before starting the conversion to avoid the above issue.

Affected Software

15 affected componentsFixes available
debian/linux<=5.10.223-1
5.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
debian/linux-6.1
6.1.129-1~deb11u1
Linux Linux kernel>=2.6.20<4.19.320
Linux Linux kernel>=4.20<5.4.282
Linux Linux kernel>=5.5<5.10.224
Linux Linux kernel>=5.11<5.15.165
Linux Linux kernel>=5.16<6.1.103
Linux Linux kernel>=6.2<6.6.44
Linux Linux kernel>=6.7<6.10.3
Linux Linux kernel=2.6.19
Linux Linux kernel=2.6.19-rc2
Linux Linux kernel=2.6.19-rc3
Linux Linux kernel=2.6.19-rc4
Linux Linux kernel=2.6.19-rc5
Linux Linux kernel=2.6.19-rc6

Event History

Aug 17, 2024
CVE Published
via MITRE·09:09 AM
Data Sourced
via MITRE·09:09 AM
Description
Data Sourced
via NVD·09:15 AM
Description
Data Sourced
via NVD·09:15 AM
RemedySeverityWeaknessAffected Software
May 1, 2025
Data Sourced
via Ubuntu·12:34 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-42305?

CVE-2024-42305 has a severity rating that indicates a potential risk of denial of service due to a page fault in the Linux kernel's ext4 filesystem.

2

How do I fix CVE-2024-42305?

To fix CVE-2024-42305, update your Linux kernel to a version greater than 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1.

3

Which versions of Linux are affected by CVE-2024-42305?

CVE-2024-42305 affects Linux kernel versions up to and including 5.10.223-1 and certain 6.x versions prior to the patched releases.

4

What component of the Linux kernel does CVE-2024-42305 involve?

CVE-2024-42305 involves the ext4 filesystem, specifically related to directory indexing and handling of dot and dotdot entries in dx_root.

5

Is there a reliable source for information on CVE-2024-42305?

The official Linux kernel Git repository contains reliable patches and information related to CVE-2024-42305.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203