Advisory Published
Updated

CVE-2024-57941: netfs: Fix the (non-)cancellation of copy when cache is temporarily disabled

First published: Tue Jan 21 2025(Updated: )

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix the (non-)cancellation of copy when cache is temporarily disabled When the caching for a cookie is temporarily disabled (e.g. due to a DIO write on that file), future copying to the cache for that file is disabled until all fds open on that file are closed. However, if netfslib is using the deprecated PG_private_2 method (such as is currently used by ceph), and decides it wants to copy to the cache, netfs_advance_write() will just bail at the first check seeing that the cache stream is unavailable, and indicate that it dealt with all the content. This means that we have no subrequests to provide notifications to drive the state machine or even to pin the request and the request just gets discarded, leaving the folios with PG_private_2 set. Fix this by jumping directly to cancel the request if the cache is not available. That way, we don't remove mark3 from the folio_queue list and netfs_pgpriv2_cancel() will clean up the folios. This was found by running the generic/013 xfstest against ceph with an active cache and the "-o fsc" option passed to ceph. That would usually hang

Credit: 416baaa9-dc9f-4396-8d5f-8c081fb06d67

Affected SoftwareAffected VersionHow to fix
Red Hat Kernel-devel

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-57941?

    CVE-2024-57941 is categorized as a low-severity vulnerability in the Linux kernel.

  • How do I fix CVE-2024-57941?

    To mitigate CVE-2024-57941, update your Linux kernel to the latest stable version where this vulnerability has been resolved.

  • What impact does CVE-2024-57941 have on system performance?

    CVE-2024-57941 primarily affects the caching mechanism for files, potentially leading to performance degradation during file operations.

  • Which versions of the Linux kernel are affected by CVE-2024-57941?

    CVE-2024-57941 impacts specific versions of the Linux kernel that utilize the netfs caching mechanism.

  • Is CVE-2024-57941 exploitable remotely?

    CVE-2024-57941 is not known to be exploitable remotely, as it relates to internal caching processes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203