cbcvebase.
CVE-2024-40943
published 2024-07-12

CVE-2024-40943: In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix races between hole punching and AIO+DIO After commit "ocfs2: return real error…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.20%
9.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix races between hole punching and AIO+DIO After commit "ocfs2: return real error code in ocfs2_dio_wr_get_block", fstests/generic/300 become from always failed to sometimes failed: [ 473.293420 ] run fstests generic/300 [ 475.296983 ] JBD2: Ignoring recovery information on journal [ 475.302473 ] ocfs2: Mounting device (253,1) on (node local, slot 0) with ordered data mode. [ 494.290998 ] OCFS2: ERROR (device dm-1): ocfs2_change_extent_flag: Owner 5668 has an extent at cpos 78723 which can no longer be found [ 494.291609 ] On-disk corruption discovered. Please run fsck.ocfs2 once the filesystem is unmounted. [ 494.292018 ] OCFS2: File system is now read-only. [ 494.292224 ] (kworker/19:11,2628,19):ocfs2_mark_extent_written:5272 ERROR: status = -30 [ 494.292602 ] (kworker/19:11,2628,19):ocfs2_dio_end_io_write:2374 ERROR: status = -3 fio: io_u error on file /mnt/scratch/racer: Read-only file system: write offset=460849152, buflen=131072 In __blockdev_direct_IO, ocfs2_dio_wr_get_block is called to add unwritten extents to a list. extents are also inserted into extent tree in ocfs2_write_begin_nolock. Then another thread call fallocate to puch a hole at one of the unwritten extent. The extent at cpos was removed by ocfs2_remove_extent(). At end io worker thread, ocfs2_search_extent_list found there is no such extent at the cpos. T1 T2 T3 inode lock ... insert extents ... inode unlock ocfs2_fallocate __ocfs2_change_file_space inode lock lock ip_alloc_sem ocfs2_remove_inode_range inode ocfs2_remove_btree_range ocfs2_remove_extent ^---remove the extent at cpos 78723 ... unlock ip_alloc_sem inode unlock ocfs2_dio_end_io ocfs2_dio_end_io_write lock ip_alloc_sem ocfs2_mark_extent_written ocfs2_change_extent_flag ocfs2_search_extent_list ^---failed to find extent ... unlock ip_alloc_sem In most filesystems, fallocate is not compatible with racing with AIO+DIO, so fix it by adding to wait for all

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= b25801038da5823bba1b5440a57ca68afc51b6bd < 3c26b5d21b1239e9c7fd31ba7d9b2d7bdbaa68d93c26b5d21b1239e9c7fd31ba7d9b2d7bdbaa68d9
linuxlinux>= b25801038da5823bba1b5440a57ca68afc51b6bd < e8e2db1adac47970a6a9225f3858e9aa0e86287fe8e2db1adac47970a6a9225f3858e9aa0e86287f
linuxlinux>= b25801038da5823bba1b5440a57ca68afc51b6bd < 050ce8af6838c71e872e982b50d3f1bec21da40e050ce8af6838c71e872e982b50d3f1bec21da40e
linuxlinux>= b25801038da5823bba1b5440a57ca68afc51b6bd < 38825ff9da91d2854dcf6d9ac320a7e641e10f2538825ff9da91d2854dcf6d9ac320a7e641e10f25
linuxlinux>= b25801038da5823bba1b5440a57ca68afc51b6bd < ea042dc2bea19d72e37c298bf65a9c341ef3fff3ea042dc2bea19d72e37c298bf65a9c341ef3fff3
linuxlinux>= b25801038da5823bba1b5440a57ca68afc51b6bd < 3c361f313d696df72f9bccf058510e9ec737b9b13c361f313d696df72f9bccf058510e9ec737b9b1
linuxlinux>= b25801038da5823bba1b5440a57ca68afc51b6bd < 117b9c009b72a6c2ebfd23484354dfee2d9570d2117b9c009b72a6c2ebfd23484354dfee2d9570d2
linuxlinux>= b25801038da5823bba1b5440a57ca68afc51b6bd < 952b023f06a24b2ad6ba67304c4c84d45bea2f18952b023f06a24b2ad6ba67304c4c84d45bea2f18
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 0 < 4.4.0-266.3004.4.0-266.300
linuxlinux_kernel>= 0 < 4.15.0-235.2474.15.0-235.247
linuxlinux_kernel>= 2.6.23 < 4.19.3174.19.317
linuxlinux_kernel>= 4.20 < 5.4.2795.4.279
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.956.1.95
linuxlinux_kernel>= 5.5 < 5.10.2215.10.221

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.