CVE-2024-46701: libfs: fix infinite directory reads for offset dir
In the Linux kernel, the following vulnerability has been resolved:
libfs: fix infinite directory reads for offset dir
After we switch tmpfs dir operations from simplediroperations to simpleoffsetdiroperations, every rename happened will fill new dentry to dest dir's maple tree(&SHMEMI(inode)->diroffsets->mt) with a free key starting with octx->newxoffset, and then set newxoffset equals to free key + 1. This will lead to infinite readdir combine with rename happened at the same time, which fail generic/736 in xfstests(detail show as below).
1. create 5000 files(1 2 3...) under one dir 2. call readdir(man 3 readdir) once, and get one entry 3. rename(entry, "TEMPFILE"), then rename("TEMPFILE", entry) 4. loop 2~3, until readdir return nothing or we loop too many times(tmpfs break test with the second condition)
We choose the same logic what commit 9b378f6ad48cf ("btrfs: fix infinite directory reads") to fix it, record the lastindex when we open dir, and do not emit the entry which index >= lastindex. The file->privatedata now used in offset dir can use directly to do this, and we also update the lastindex when we llseek the dir file.
[brauner: only update lastindex after seek when offset is zero like Jan suggested]
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46701?
CVE-2024-46701 is classified as a vulnerability in the Linux kernel affecting directory operations.
How do I fix CVE-2024-46701?
To fix CVE-2024-46701, upgrade the Linux kernel to a version that is patched, such as 5.10.223-1, 5.10.226-1, or 6.12.11-1.
Which versions of the Linux kernel are affected by CVE-2024-46701?
CVE-2024-46701 affects Linux kernel versions from 6.6 to 6.10.7 and specific release candidates 6.11-rc1, 6.11-rc2, and 6.11-rc3.
What type of vulnerability is CVE-2024-46701?
CVE-2024-46701 addresses an infinite directory reads issue in libfs related to the kernel directory operations.
Is CVE-2024-46701 a remote or local vulnerability?
CVE-2024-46701 is classified as a local vulnerability affecting filesystem operations in the Linux kernel.