In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to do sanity check on block address in f2fs_do_zero_range()
As Yanming reported in bugzilla:
https://bugzilla.kernel.org/show_bug.cgi?id=215894
I have encountered a bug in F2FS file system in kernel v5.17.
I have uploaded the system call sequence as case.c, and a fuzzed image can be found in google net disk
The kernel should enable CONFIG_KASAN=y and CONFIG_KASAN_INLINE=y. You can reproduce the bug by running the following commands:
kernel BUG at fs/f2fs/segment.c:2291! Call Trace: f2fs_invalidate_blocks+0x193/0x2d0 f2fs_fallocate+0x2593/0x4a70 vfs_fallocate+0x2a5/0xac0 ksys_fallocate+0x35/0x70 __x64_sys_fallocate+0x8e/0xf0 do_syscall_64+0x3b/0x90 entry_SYSCALL_64_after_hwframe+0x44/0xae
The root cause is, after image was fuzzed, block mapping info in inode will be inconsistent with SIT table, so in f2fs_fallocate(), it will cause panic when updating SIT with invalid blkaddr.
Let's fix the issue by adding sanity check on block address before updating SIT table with it.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-realtimeUpgrade linux-gcp-5.15Upgrade linux-raspiUpgrade linux-aws-5.4Upgrade linux-aws-5.15Upgrade linux-kvmUpgrade linux-oracle-5.4Upgrade linux-azureUpgrade linux-intel-iotg-5.15Upgrade linux-gcpUpgrade linux-hwe-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-iotUpgrade linux-awsUpgrade linux-gkeUpgrade linux-raspi-5.4Upgrade linux-bluefieldUpgrade linux-riscv-5.15Upgrade linux-intel-iotgUpgrade linux-ibmUpgrade linux-fipsUpgrade linux-nvidiaUpgrade linux-oracleUpgrade linux-gkeopUpgrade linux-lowlatencyUpgrade linux-gcp-fipsUpgrade linuxUpgrade linux-oracle-5.15Upgrade linux-gcp-5.4Upgrade linux-ibm-5.4Upgrade linux-azure-5.4Upgrade linux-azure-fipsUpgrade linux-azure-5.15Upgrade linux-hwe-5.4Upgrade linux-aws-fips | Mar 3, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub