CVE-2023-52705
published 2024-05-21CVE-2023-52705: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix underflow in second superblock position calculations Macro…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix underflow in second superblock position calculations
Macro NILFS_SB2_OFFSET_BYTES, which computes the position of the second
superblock, underflows when the argument device size is less than 4096
bytes. Therefore, when using this macro, it is necessary to check in
advance that the device size is not less than a lower limit, or at least
that underflow does not occur.
The current nilfs2 implementation lacks this check, causing out-of-bound
block access when mounting devices smaller than 4096 bytes:
I/O error, dev loop0, sector 36028797018963960 op 0x0:(READ) flags 0x0
phys_seg 1 prio class 2
NILFS (loop0): unable to read secondary superblock (blocksize = 1024)
In addition, when trying to resize the filesystem to a size below 4096
bytes, this underflow occurs in nilfs_resize_fs(), passing a huge number
of segments to nilfs_sufile_resize(), corrupting parameters such as the
number of segments in superblocks. This causes excessive loop iterations
in nilfs_sufile_resize() during a subsequent resize ioctl, causing
semaphore ns_segctor_sem to block for a long time and hang the writer
thread:
INFO: task segctord:5067 blocked for more than 143 seconds.
Not tainted 6.2.0-rc8-syzkaller-00015-gf6feea56f66d #0
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:segctord state:D stack:23456 pid:5067 ppid:2
flags:0x00004000
Call Trace:
context_switch kernel/sched/core.c:5293 [inline]
__schedule+0x1409/0x43f0 kernel/sched/core.c:6606
schedule+0xc3/0x190 kernel/sched/core.c:6682
rwsem_down_write_slowpath+0xfcf/0x14a0 kernel/locking/rwsem.c:1190
nilfs_transaction_lock+0x25c/0x4f0 fs/nilfs2/segment.c:357
nilfs_segctor_thread_construct fs/nilfs2/segment.c:2486 [inline]
nilfs_segctor_thread+0x52f/0x1140 fs/nilfs2/segment.c:2570
kthread+0x270/0x300 kernel/kthread.c:376
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:308
...
Call Trace:
folio_mark_accessed+0x51c/0xf00 mm/sw
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.15-1 (bookworm) | linux 6.1.15-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= e339ad31f59925b48a92ee3947692fdf9758b8c7 < 2f7a1135b202977b82457adde7db6c390056863b | 2f7a1135b202977b82457adde7db6c390056863b |
| linux | linux | >= e339ad31f59925b48a92ee3947692fdf9758b8c7 < b96591e2c35c8b47db0ec816b5fc6cb8868000ff | b96591e2c35c8b47db0ec816b5fc6cb8868000ff |
| linux | linux | >= e339ad31f59925b48a92ee3947692fdf9758b8c7 < 52844d8382cd9166d708032def8905ffc3ae550f | 52844d8382cd9166d708032def8905ffc3ae550f |
| linux | linux | >= e339ad31f59925b48a92ee3947692fdf9758b8c7 < 0ee5ed0126a2211f7174492da2ca2c29f43755c5 | 0ee5ed0126a2211f7174492da2ca2c29f43755c5 |
| linux | linux | >= e339ad31f59925b48a92ee3947692fdf9758b8c7 < a158782b56b070485d54d25fc9aaf2c8f3752205 | a158782b56b070485d54d25fc9aaf2c8f3752205 |
| linux | linux | >= e339ad31f59925b48a92ee3947692fdf9758b8c7 < a8ef5109f93cea9933bbac0455d8c18757b3fcb4 | a8ef5109f93cea9933bbac0455d8c18757b3fcb4 |
| linux | linux | >= e339ad31f59925b48a92ee3947692fdf9758b8c7 < 99b9402a36f0799f25feee4465bfa4b8dfa74b4d | 99b9402a36f0799f25feee4465bfa4b8dfa74b4d |
| linux | linux_kernel | < 4.14.306 | 4.14.306 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.15-1 | 6.1.15-1 |
| linux | linux_kernel | >= 0 < 6.1.15-1 | 6.1.15-1 |
| linux | linux_kernel | >= 0 < 6.1.15-1 | 6.1.15-1 |
| linux | linux_kernel | >= 4.15 < 4.19.273 | 4.19.273 |
| linux | linux_kernel | >= 4.20 < 5.4.232 | 5.4.232 |
| linux | linux_kernel | >= 5.11 < 5.15.95 | 5.15.95 |
| linux | linux_kernel | >= 5.16 < 6.1.13 | 6.1.13 |
| linux | linux_kernel | >= 5.5 < 5.10.169 | 5.10.169 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: nilfs2: fix underflow in second superblock position calculations
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2023-52705 [MEDIUM] CWE-124 kernel: nilfs2: fix underflow in second superblock position calculations
kernel: nilfs2: fix underflow in second superblock position calculations
In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix underflow in second superblock position calculations
Macro NILFS_SB2_OFFSET_BYTES, which computes the position of the second
superblock, underflows when the argument device size is less than 4096
bytes. Therefore, when using this macro, it is necessary to check in
advance that the device size is not less than a lower limit, or at least
that underflow does not occur.
The current nilfs2 implementation lacks this check, causing out-of-bound
block access when mounting devices smaller than 4096 bytes:
I/O error, dev loop0, sector 36028797018963960 op 0x0:(READ) flags 0x0
phys_seg 1 prio class 2
NILFS (loop0): unable to read secondary superbloc
Debian
CVE-2023-52705: linux - In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix...
vendor_debian·2023·CVSS 5.5
CVE-2023-52705 [MEDIUM] CVE-2023-52705: linux - In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix...
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix underflow in second superblock position calculations Macro NILFS_SB2_OFFSET_BYTES, which computes the position of the second superblock, underflows when the argument device size is less than 4096 bytes. Therefore, when using this macro, it is necessary to check in advance that the device size is not less than a lower limit, or at least that underflow does not occur. The current nilfs2 implementation lacks this check, causing out-of-bound block access when mounting devices smaller than 4096 bytes: I/O error, dev loop0, sector 36028797018963960 op 0x0:(READ) flags 0x0 phys_seg 1 prio class 2 NILFS (loop0): unable to read secondary superblock (blocksize = 1024) In addition, when trying to resize the filesystem to
GHSA
GHSA-rwq9-67rv-755x: In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix underflow in second superblock position calculations
Macro NILFS_SB2
ghsa_unreviewed·2024-05-21
CVE-2023-52705 [MEDIUM] CWE-191 GHSA-rwq9-67rv-755x: In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix underflow in second superblock position calculations
Macro NILFS_SB2
In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix underflow in second superblock position calculations
Macro NILFS_SB2_OFFSET_BYTES, which computes the position of the second
superblock, underflows when the argument device size is less than 4096
bytes. Therefore, when using this macro, it is necessary to check in
advance that the device size is not less than a lower limit, or at least
that underflow does not occur.
The current nilfs2 implementation lacks this check, causing out-of-bound
block access when mounting devices smaller than 4096 bytes:
I/O error, dev loop0, sector 36028797018963960 op 0x0:(READ) flags 0x0
phys_seg 1 prio class 2
NILFS (loop0): unable to read secondary superblock (blocksize = 1024)
In addition, when trying to resize the filesyste
OSV
CVE-2023-52705: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix underflow in second superblock position calculations Macro NILFS_SB2_O
osv·2024-05-21·CVSS 5.5
CVE-2023-52705 [MEDIUM] CVE-2023-52705: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix underflow in second superblock position calculations Macro NILFS_SB2_O
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix underflow in second superblock position calculations Macro NILFS_SB2_OFFSET_BYTES, which computes the position of the second superblock, underflows when the argument device size is less than 4096 bytes. Therefore, when using this macro, it is necessary to check in advance that the device size is not less than a lower limit, or at least that underflow does not occur. The current nilfs2 implementation lacks this check, causing out-of-bound block access when mounting devices smaller than 4096 bytes: I/O error, dev loop0, sector 36028797018963960 op 0x0:(READ) flags 0x0 phys_seg 1 prio class 2 NILFS (loop0): unable to read secondary superblock (blocksize = 1024) In addition, when trying to resize the filesystem to
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0ee5ed0126a2211f7174492da2ca2c29f43755c5https://git.kernel.org/stable/c/2f7a1135b202977b82457adde7db6c390056863bhttps://git.kernel.org/stable/c/52844d8382cd9166d708032def8905ffc3ae550fhttps://git.kernel.org/stable/c/99b9402a36f0799f25feee4465bfa4b8dfa74b4dhttps://git.kernel.org/stable/c/a158782b56b070485d54d25fc9aaf2c8f3752205https://git.kernel.org/stable/c/a8ef5109f93cea9933bbac0455d8c18757b3fcb4https://git.kernel.org/stable/c/b96591e2c35c8b47db0ec816b5fc6cb8868000ffhttps://git.kernel.org/stable/c/0ee5ed0126a2211f7174492da2ca2c29f43755c5https://git.kernel.org/stable/c/2f7a1135b202977b82457adde7db6c390056863bhttps://git.kernel.org/stable/c/52844d8382cd9166d708032def8905ffc3ae550fhttps://git.kernel.org/stable/c/99b9402a36f0799f25feee4465bfa4b8dfa74b4dhttps://git.kernel.org/stable/c/a158782b56b070485d54d25fc9aaf2c8f3752205https://git.kernel.org/stable/c/a8ef5109f93cea9933bbac0455d8c18757b3fcb4https://git.kernel.org/stable/c/b96591e2c35c8b47db0ec816b5fc6cb8868000ff
2024-05-21
Published