CVE-2024-46785: eventfs: Use list_del_rcu() for SRCU protected list variable
In the Linux kernel, the following vulnerability has been resolved:
eventfs: Use listdelrcu() for SRCU protected list variable
Chi Zhiling reported:
We found a null pointer accessing in tracefs[1], the reason is that the variable 'eichild' is set to LISTPOISON1, that means the list was removed in eventfsremoverec. so when access the eichild->isfreed, the panic triggered.
by the way, the following script can reproduce this panic
loop1 (){ while true do echo "p:kp submitbio" > /sys/kernel/debug/tracing/kprobeevents echo "" > /sys/kernel/debug/tracing/kprobeevents done } loop2 (){ while true do tree /sys/kernel/debug/tracing/events/kprobes/ done } loop1 & loop2
[1]: [ 1147.959632][T17331] Unable to handle kernel paging request at virtual address dead000000000150 [ 1147.968239][T17331] Mem abort info: [ 1147.971739][T17331] ESR = 0x0000000096000004 [ 1147.976172][T17331] EC = 0x25: DABT (current EL), IL = 32 bits [ 1147.982171][T17331] SET = 0, FnV = 0 [ 1147.985906][T17331] EA = 0, S1PTW = 0 [ 1147.989734][T17331] FSC = 0x04: level 0 translation fault [ 1147.995292][T17331] Data abort info: [ 1147.998858][T17331] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [ 1148.005023][T17331] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 1148.010759][T17331] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 1148.016752][T17331] [dead000000000150] address between user and kernel address ranges [ 1148.024571][T17331] Internal error: Oops: 0000000096000004 [#1] SMP [ 1148.030825][T17331] Modules linked in: teammodeloadbalance team nlmon actgact clsflower schingress bonding tls macvlan dummy ibcore bridge stp llc veth amdgpu amdxcp mfdcore gpusched drmexec drmbuddy radeon crct10difce video drmsuballochelper ghashce drmttmhelper sha2ce ttm sha256arm64 i2calgobit sha1ce sbsagwdt cp210x drmdisplayhelper cec srmod cdrom drmkmshelper binfmtmisc sg loop fuse drm dmmod nfnetlink iptables autofs4 [last unloaded: tls] [ 1148.072808][T17331] CPU: 3 PID: 17331 Comm: ls Tainted: G W ------- ---- 6.6.43 #2 [ 1148.081751][T17331] Source Version: 21b3b386e948bedd29369af66f3e98ab01b1c650 [ 1148.088783][T17331] Hardware name: Greatwall GW-001M1A-FTF/GW-001M1A-FTF, BIOS KunLun BIOS V4.0 07/16/2020 [ 1148.098419][T17331] pstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 1148.106060][T17331] pc : eventfsiterate+0x2c0/0x398 [ 1148.111017][T17331] lr : eventfsiterate+0x2fc/0x398 [ 1148.115969][T17331] sp : ffff80008d56bbd0 [ 1148.119964][T17331] x29: ffff80008d56bbf0 x28: ffff001ff5be2600 x27: 0000000000000000 [ 1148.127781][T17331] x26: ffff001ff52ca4e0 x25: 0000000000009977 x24: dead000000000100 [ 1148.135598][T17331] x23: 0000000000000000 x22: 000000000000000b x21: ffff800082645f10 [ 1148.143415][T17331] x20: ffff001fddf87c70 x19: ffff80008d56bc90 x18: 0000000000000000 [ 1148.151231][T17331] x17: 0000000000000000 x16: 0000000000000000 x15: ffff001ff52ca4e0 [ 1148.159048][T17331] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000 [ 1148.166864][T17331] x11: 0000000000000000 x10: 0000000000000000 x9 : ffff8000804391d0 [ 1148.174680][T17331] x8 : 0000000180000000 x7 : 0000000000000018 x6 : 0000aaab04b92862 [ 1148.182498][T17331] x5 : 0000aaab04b92862 x4 : 0000000080000000 x3 : 0000000000000068 [ 1148.190314][T17331] x2 : 000000000000000f x1 : 0000000000007ea8 x0 : 0000000000000001 [ 1148.198131][T17331] Call trace: [ 1148.201259][T17331] eventfsiterate+0x2c0/0x398 [ 1148.205864][T17331] iteratedir+0x98/0x188 [ 1148.210036][T17331] arm64sysgetdents64+0x78/0x160 [ 1148.215161][T17331] invokesyscall+0x78/0x108 [ 1148.219593][T17331] el0svccommon.constprop.0+0x48/0xf0 [ 1148.224977][T17331] doel0svc+0x24/0x38 [ 1148.228974][T17331] el0svc+0x40/0x168 [ 1148.232798][T17 ---truncated---
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46785?
CVE-2024-46785 is classified as a medium severity vulnerability in the Linux kernel.
How do I fix CVE-2024-46785?
To fix CVE-2024-46785, update the Linux kernel to a version that includes the security patches for this vulnerability.
Which versions of the Linux kernel are affected by CVE-2024-46785?
CVE-2024-46785 affects Linux kernel versions from 6.6.18 to less than 6.6.51, as well as versions between 6.7.6 and 6.8, and some release candidates of version 6.11.
Who reported CVE-2024-46785?
CVE-2024-46785 was reported by Chi Zhiling.
What type of vulnerability is CVE-2024-46785?
CVE-2024-46785 is a null pointer access vulnerability in the eventfs component of the Linux kernel.