CVE-2024-49883: ext4: aovid use-after-free in ext4_ext_insert_extent()
In the Linux kernel, the following vulnerability has been resolved:
ext4: aovid use-after-free in ext4extinsertextent()
As Ojaswin mentioned in Link, in ext4extinsertextent(), if the path is reallocated in ext4extcreatenewleaf(), we'll use the stale path and cause UAF. Below is a sample trace with dummy values:
ext4extinsertextent path = ppath = 2000 ext4extcreatenewleaf(ppath) ext4findextent(ppath) path = ppath = 2000 if (depth > path[0].pmaxdepth) kfree(path = 2000); ppath = path = NULL; path = kcalloc() = 3000 ppath = 3000; return path; / here path is still 2000, UAF! / eh = path[depth].phdr
================================================================== BUG: KASAN: slab-use-after-free in ext4extinsertextent+0x26d4/0x3330 Read of size 8 at addr ffff8881027bf7d0 by task kworker/u36:1/179 CPU: 3 UID: 0 PID: 179 Comm: kworker/u6:1 Not tainted 6.11.0-rc2-dirty #866 Call Trace: <TASK> ext4extinsertextent+0x26d4/0x3330 ext4extmapblocks+0xe22/0x2d40 ext4mapblocks+0x71e/0x1700 ext4dowritepages+0x1290/0x2800 [...]
Allocated by task 179: ext4findextent+0x81c/0x1f70 ext4extmapblocks+0x146/0x2d40 ext4mapblocks+0x71e/0x1700 ext4dowritepages+0x1290/0x2800 ext4writepages+0x26d/0x4e0 dowritepages+0x175/0x700 [...]
Freed by task 179: kfree+0xcb/0x240 ext4findextent+0x7c0/0x1f70 ext4extinsertextent+0xa26/0x3330 ext4extmapblocks+0xe22/0x2d40 ext4mapblocks+0x71e/0x1700 ext4dowritepages+0x1290/0x2800 ext4writepages+0x26d/0x4e0 dowritepages+0x175/0x700 [...] ==================================================================
So use ppath to update the path to avoid the above problem.
Other sources
In the Linux kernel, the following vulnerability has been resolved:
ext4: aovid use-after-free in ext4extinsertextent()
As Ojaswin mentioned in Link, in ext4extinsertextent(), if the path is reallocated in ext4extcreatenewleaf(), we'll use the stale path and cause UAF. Below is a sample trace with dummy values:
ext4extinsertextent path = ppath = 2000 ext4extcreatenewleaf(ppath) ext4findextent(ppath) path = ppath = 2000 if (depth > path[0].pmaxdepth) kfree(path = 2000); ppath = path = NULL; path = kcalloc() = 3000 ppath = 3000; return path; / here path is still 2000, UAF! / eh = path[depth].phdr
================================================================== BUG: KASAN: slab-use-after-free in ext4extinsertextent+0x26d4/0x3330 Read of size 8 at addr ffff8881027bf7d0 by task kworker/u36:1/179 CPU: 3 UID: 0 PID: 179 Comm: kworker/u6:1 Not tainted 6.11.0-rc2-dirty #866 Call Trace: <TASK> ext4extinsertextent+0x26d4/0x3330 ext4extmapblocks+0xe22/0x2d40 ext4mapblocks+0x71e/0x1700 ext4dowritepages+0x1290/0x2800 [...]
Allocated by task 179: ext4findextent+0x81c/0x1f70 ext4extmapblocks+0x146/0x2d40 ext4mapblocks+0x71e/0x1700 ext4dowritepages+0x1290/0x2800 ext4writepages+0x26d/0x4e0 dowritepages+0x175/0x700 [...]
Freed by task 179: kfree+0xcb/0x240 ext4findextent+0x7c0/0x1f70 ext4extinsertextent+0xa26/0x3330 ext4extmapblocks+0xe22/0x2d40 ext4mapblocks+0x71e/0x1700 ext4dowritepages+0x1290/0x2800 ext4writepages+0x26d/0x4e0 dowritepages+0x175/0x700 [...] ==================================================================
So use ppath to update the path to avoid the above problem.
— NVD
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1 - Configuration
Modify ext4_ext_insert_extent() so that when ext4_ext_create_new_leaf(ppath) reallocates the path, the code updates the caller’s pointer via *ppath and uses the updated *ppath value; do not continue using the stale local 'path' value after the reallocation. (Text cites: “So use *ppath to update the path to avoid the above problem.”)
Linux kernel ext4 (ext4_ext_insert_extent/ext4_ext_create_new_leaf) Use of *ppath when ext4_ext_create_new_leaf() reallocates the path = Update *ppath (instead of continuing to use the stale local path pointer) - Compensating control
Reboot/restart the affected system after applying the ext4 kernel fix so the updated ext4 code path is used (since the issue is in the running kernel’s ext4 implementation).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49883?
CVE-2024-49883 has not been assigned a CVSS score but is considered to potentially cause significant security concerns due to the use-after-free vulnerability.
How do I fix CVE-2024-49883?
To fix CVE-2024-49883, ensure that your Linux kernel is updated to a patched version listed in the vulnerability's references.
What versions of the Linux kernel are affected by CVE-2024-49883?
CVE-2024-49883 affects multiple versions of the Linux kernel, specifically those between 3.18 and 5.10.227, 5.11 and 5.15.168, 5.16 and 6.1.113, and others.
What exploit scenarios are associated with CVE-2024-49883?
CVE-2024-49883 could allow an attacker to execute arbitrary code with elevated privileges due to a use-after-free condition.
Is CVE-2024-49883 actively being exploited in the wild?
As of now, there have been no confirmed reports of active exploitation of CVE-2024-49883 in the wild.