cbcvebase.
CVE-2024-57896
published 2025-01-15

CVE-2024-57896: In the Linux kernel, the following vulnerability has been resolved: btrfs: flush delalloc workers queue before stopping cleaner kthread during unmount During…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.2th percentile
In the Linux kernel, the following vulnerability has been resolved: btrfs: flush delalloc workers queue before stopping cleaner kthread during unmount During the unmount path, at close_ctree(), we first stop the cleaner kthread, using kthread_stop() which frees the associated task_struct, and then stop and destroy all the work queues. However after we stopped the cleaner we may still have a worker from the delalloc_workers queue running inode.c:submit_compressed_extents(), which calls btrfs_add_delayed_iput(), which in turn tries to wake up the cleaner kthread - which was already destroyed before, resulting in a use-after-free on the task_struct. Syzbot reported this with the following stack traces: BUG: KASAN: slab-use-after-free in __lock_acquire+0x78/0x2100 kernel/locking/lockdep.c:5089 Read of size 8 at addr ffff8880259d2818 by task kworker/u8:3/52 CPU: 1 UID: 0 PID: 52 Comm: kworker/u8:3 Not tainted 6.13.0-rc1-syzkaller-00002-gcdd30ebb1b9f #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 Workqueue: btrfs-delalloc btrfs_work_helper Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0x169/0x550 mm/kasan/report.c:489 kasan_report+0x143/0x180 mm/kasan/report.c:602 __lock_acquire+0x78/0x2100 kernel/locking/lockdep.c:5089 lock_acquire+0x1ed/0x550 kernel/locking/lockdep.c:5849 __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline] _raw_spin_lock_irqsave+0xd5/0x120 kernel/locking/spinlock.c:162 class_raw_spinlock_irqsave_constructor include/linux/spinlock.h:551 [inline] try_to_wake_up+0xc2/0x1470 kernel/sched/core.c:4205 submit_compressed_extents+0xdf/0x16e0 fs/btrfs/inode.c:1615 run_ordered_work fs/btrfs/async-thread.c:288 [inline] btrfs_work_helper+0x96f/0xc40 fs/btrfs/async-thread.c:324 process_one_work kernel/workqueue.c:3229 [inline] process_scheduled_works+0xa66/0x1840 kernel/work

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.124-1 (bookworm)linux 6.1.124-1 (bookworm)
debianlinux-6.1< linux 6.1.124-1 (bookworm)linux 6.1.124-1 (bookworm)
linuxlinux
linuxlinux>= fd340d0f68cc87badfc9efcb226f23a5428826a0 < a2718ed1eb8c3611b63f8933c7e68c8821fe2808a2718ed1eb8c3611b63f8933c7e68c8821fe2808
linuxlinux>= fd340d0f68cc87badfc9efcb226f23a5428826a0 < 63f4b594a688bf922e8691f0784679aa7af7988c63f4b594a688bf922e8691f0784679aa7af7988c
linuxlinux>= fd340d0f68cc87badfc9efcb226f23a5428826a0 < 1ea629e7bb2fb40555e5e01a1b5095df312870171ea629e7bb2fb40555e5e01a1b5095df31287017
linuxlinux>= fd340d0f68cc87badfc9efcb226f23a5428826a0 < 35916b2f96505a18dc7242a115611b718d9de72535916b2f96505a18dc7242a115611b718d9de725
linuxlinux>= fd340d0f68cc87badfc9efcb226f23a5428826a0 < d77a3a99b53d12c061c007cdc96df38825dee476d77a3a99b53d12c061c007cdc96df38825dee476
linuxlinux>= fd340d0f68cc87badfc9efcb226f23a5428826a0 < f10bef73fb355e3fc85e63a50386798be68ff486f10bef73fb355e3fc85e63a50386798be68ff486
linuxlinux_kernel< 5.10.2335.10.233
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.124-16.1.124-1
linuxlinux_kernel>= 0 < 6.12.9-16.12.9-1
linuxlinux_kernel>= 0 < 6.12.9-16.12.9-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 5.11 < 5.15.1765.15.176
linuxlinux_kernel>= 5.16 < 6.1.1246.1.124
linuxlinux_kernel>= 6.2 < 6.6.706.6.70
linuxlinux_kernel>= 6.7 < 6.12.96.12.9

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.