cbcvebase.
CVE-2024-26956
published 2024-05-01

CVE-2024-26956: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix failure to detect DAT corruption in btree and direct mappings Patch series…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.0th percentile
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix failure to detect DAT corruption in btree and direct mappings Patch series "nilfs2: fix kernel bug at submit_bh_wbc()". This resolves a kernel BUG reported by syzbot. Since there are two flaws involved, I've made each one a separate patch. The first patch alone resolves the syzbot-reported bug, but I think both fixes should be sent to stable, so I've tagged them as such. This patch (of 2): Syzbot has reported a kernel bug in submit_bh_wbc() when writing file data to a nilfs2 file system whose metadata is corrupted. There are two flaws involved in this issue. The first flaw is that when nilfs_get_block() locates a data block using btree or direct mapping, if the disk address translation routine nilfs_dat_translate() fails with internal code -ENOENT due to DAT metadata corruption, it can be passed back to nilfs_get_block(). This causes nilfs_get_block() to misidentify an existing block as non-existent, causing both data block lookup and insertion to fail inconsistently. The second flaw is that nilfs_get_block() returns a successful status in this inconsistent state. This causes the caller __block_write_begin_int() or others to request a read even though the buffer is not mapped, resulting in a BUG_ON check for the BH_Mapped flag in submit_bh_wbc() failing. This fixes the first issue by changing the return value to code -EINVAL when a conversion using DAT fails with code -ENOENT, avoiding the conflicting condition that leads to the kernel bug described above. Here, code -EINVAL indicates that metadata corruption was detected during the block lookup, which will be properly handled as a file system error and converted to -EIO when passing through the nilfs2 bmap layer.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= c3a7abf06ce719a51139e62a034590be99abbc2c < b67189690eb4b7ecc84ae16fa1e880e0123eaa35b67189690eb4b7ecc84ae16fa1e880e0123eaa35
linuxlinux>= c3a7abf06ce719a51139e62a034590be99abbc2c < 9cbe1ad5f4354f4df1445e5f4883983328cd6d8e9cbe1ad5f4354f4df1445e5f4883983328cd6d8e
linuxlinux>= c3a7abf06ce719a51139e62a034590be99abbc2c < c3b5c5c31e723b568f83d8cafab8629d9d830ffbc3b5c5c31e723b568f83d8cafab8629d9d830ffb
linuxlinux>= c3a7abf06ce719a51139e62a034590be99abbc2c < 2e2619ff5d0def4bb6c2037a32a6eaa28dd95c842e2619ff5d0def4bb6c2037a32a6eaa28dd95c84
linuxlinux>= c3a7abf06ce719a51139e62a034590be99abbc2c < 46b832e09d43b394ac0f6d9485d2b1a06593f0b746b832e09d43b394ac0f6d9485d2b1a06593f0b7
linuxlinux>= c3a7abf06ce719a51139e62a034590be99abbc2c < f69e81396aea66304d214f175aa371f1b5578862f69e81396aea66304d214f175aa371f1b5578862
linuxlinux>= c3a7abf06ce719a51139e62a034590be99abbc2c < a8e4d098de1c0f4c5c1f2ed4633a860f0da6d713a8e4d098de1c0f4c5c1f2ed4633a860f0da6d713
linuxlinux>= c3a7abf06ce719a51139e62a034590be99abbc2c < 82827ca21e7c8a91384c5baa656f78a5adfa4ab482827ca21e7c8a91384c5baa656f78a5adfa4ab4
linuxlinux>= c3a7abf06ce719a51139e62a034590be99abbc2c < f2f26b4a84a0ef41791bd2d70861c8eac748f4baf2f26b4a84a0ef41791bd2d70861c8eac748f4ba
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 2.6.31 < 4.19.3124.19.312
linuxlinux_kernel>= 4.20 < 5.4.2745.4.274
linuxlinux_kernel>= 5.11 < 5.15.1545.15.154
linuxlinux_kernel>= 5.16 < 6.1.846.1.84
linuxlinux_kernel>= 5.5 < 5.10.2155.10.215
linuxlinux_kernel>= 6.2 < 6.6.246.6.24

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.