cbcvebase.
CVE-2024-35849
published 2024-05-17

CVE-2024-35849: In the Linux kernel, the following vulnerability has been resolved: btrfs: fix information leak in btrfs_ioctl_logical_to_ino() Syzbot reported the following…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.26%
17.2th percentile
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix information leak in btrfs_ioctl_logical_to_ino() Syzbot reported the following information leak for in btrfs_ioctl_logical_to_ino(): BUG: KMSAN: kernel-infoleak in instrument_copy_to_user include/linux/instrumented.h:114 [inline] BUG: KMSAN: kernel-infoleak in _copy_to_user+0xbc/0x110 lib/usercopy.c:40 instrument_copy_to_user include/linux/instrumented.h:114 [inline] _copy_to_user+0xbc/0x110 lib/usercopy.c:40 copy_to_user include/linux/uaccess.h:191 [inline] btrfs_ioctl_logical_to_ino+0x440/0x750 fs/btrfs/ioctl.c:3499 btrfs_ioctl+0x714/0x1260 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:904 [inline] __se_sys_ioctl+0x261/0x450 fs/ioctl.c:890 __x64_sys_ioctl+0x96/0xe0 fs/ioctl.c:890 x64_sys_call+0x1883/0x3b50 arch/x86/include/generated/asm/syscalls_64.h:17 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Uninit was created at: __kmalloc_large_node+0x231/0x370 mm/slub.c:3921 __do_kmalloc_node mm/slub.c:3954 [inline] __kmalloc_node+0xb07/0x1060 mm/slub.c:3973 kmalloc_node include/linux/slab.h:648 [inline] kvmalloc_node+0xc0/0x2d0 mm/util.c:634 kvmalloc include/linux/slab.h:766 [inline] init_data_container+0x49/0x1e0 fs/btrfs/backref.c:2779 btrfs_ioctl_logical_to_ino+0x17c/0x750 fs/btrfs/ioctl.c:3480 btrfs_ioctl+0x714/0x1260 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:904 [inline] __se_sys_ioctl+0x261/0x450 fs/ioctl.c:890 __x64_sys_ioctl+0x96/0xe0 fs/ioctl.c:890 x64_sys_call+0x1883/0x3b50 arch/x86/include/generated/asm/syscalls_64.h:17 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Bytes 40-65535 of 65536 are uninitialized Memory access of size 65536 starts at ffff888045a40000 This happens, because we're copying a 'struct btrfs_data_container' back to user-space. This bt

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux>= a542ad1bafc7df9fc16de8a6894b350a4df75572 < 689efe22e9b5b7d9d523119a9a5c3c17107a0772689efe22e9b5b7d9d523119a9a5c3c17107a0772
linuxlinux>= a542ad1bafc7df9fc16de8a6894b350a4df75572 < 73db209dcd4ae026021234d40cfcb2fb5b564b8673db209dcd4ae026021234d40cfcb2fb5b564b86
linuxlinux>= a542ad1bafc7df9fc16de8a6894b350a4df75572 < 30189e54ba80e3209d34cfeea87b848f6ae025e630189e54ba80e3209d34cfeea87b848f6ae025e6
linuxlinux>= a542ad1bafc7df9fc16de8a6894b350a4df75572 < e58047553a4e859dafc8d1d901e1de77c9dd922de58047553a4e859dafc8d1d901e1de77c9dd922d
linuxlinux>= a542ad1bafc7df9fc16de8a6894b350a4df75572 < 8bdbcfaf3eac42f98e5486b3d7e130fa287811f68bdbcfaf3eac42f98e5486b3d7e130fa287811f6
linuxlinux>= a542ad1bafc7df9fc16de8a6894b350a4df75572 < 3a63cee1a5e14a3e52c19142c61dd5fcb524f6dc3a63cee1a5e14a3e52c19142c61dd5fcb524f6dc
linuxlinux>= a542ad1bafc7df9fc16de8a6894b350a4df75572 < fddc19631c51d9c17d43e9f822a7bc403af88d54fddc19631c51d9c17d43e9f822a7bc403af88d54
linuxlinux>= a542ad1bafc7df9fc16de8a6894b350a4df75572 < 2f7ef5bb4a2f3e481ef05fab946edb97c84f67cf2f7ef5bb4a2f3e481ef05fab946edb97c84f67cf
linuxlinux_kernel< 4.19.3134.19.313
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 0 < 4.4.0-273.3074.4.0-273.307
linuxlinux_kernel>= 0 < 4.15.0-242.2544.15.0-242.254
linuxlinux_kernel>= 4.20 < 5.4.2755.4.275
linuxlinux_kernel>= 5.11 < 5.15.1585.15.158
linuxlinux_kernel>= 5.16 < 6.1.906.1.90

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.