Bug 2301468 (CVE-2024-42105) - CVE-2024-42105 kernel: nilfs2: fix inode number range checks
Summary: CVE-2024-42105 kernel: nilfs2: fix inode number range checks
Keywords:
Status: NEW
Alias: CVE-2024-42105
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2301763
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-07-30 08:21 UTC by OSIDB Bzimport
Modified: 2024-09-23 08:26 UTC (History)
4 users (show)

Fixed In Version: kernel 4.19.318, kernel 5.4.280, kernel 5.10.222, kernel 5.15.163, kernel 6.1.98, kernel 6.6.39, kernel 6.9.9, kernel 6.10
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2024-07-30 08:21:49 UTC
In the Linux kernel, the following vulnerability has been resolved:

nilfs2: fix inode number range checks

Patch series "nilfs2: fix potential issues related to reserved inodes".

This series fixes one use-after-free issue reported by syzbot, caused by
nilfs2's internal inode being exposed in the namespace on a corrupted
filesystem, and a couple of flaws that cause problems if the starting
number of non-reserved inodes written in the on-disk super block is
intentionally (or corruptly) changed from its default value.  


This patch (of 3):

In the current implementation of nilfs2, "nilfs->ns_first_ino", which
gives the first non-reserved inode number, is read from the superblock,
but its lower limit is not checked.

As a result, if a number that overlaps with the inode number range of
reserved inodes such as the root directory or metadata files is set in the
super block parameter, the inode number test macros (NILFS_MDT_INODE and
NILFS_VALID_INODE) will not function properly.

In addition, these test macros use left bit-shift calculations using with
the inode number as the shift count via the BIT macro, but the result of a
shift calculation that exceeds the bit width of an integer is undefined in
the C specification, so if "ns_first_ino" is set to a large value other
than the default value NILFS_USER_INO (=11), the macros may potentially
malfunction depending on the environment.

Fix these issues by checking the lower bound of "nilfs->ns_first_ino" and
by preventing bit shifts equal to or greater than the NILFS_USER_INO
constant in the inode number test macros.

Also, change the type of "ns_first_ino" from signed integer to unsigned
integer to avoid the need for type casting in comparisons such as the
lower bound check introduced this time.

Comment 1 Mauro Matteo Cascella 2024-07-30 18:29:26 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024073020-CVE-2024-42105-276f@gregkh/T

Comment 2 Mauro Matteo Cascella 2024-07-30 18:29:47 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 2301763]


Note You need to log in before you can comment on or make changes to this bug.