In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix use-after-free bug of ns_writer on remount
If a nilfs2 filesystem is downgraded to read-only due to metadata corruption on disk and is remounted read/write, or if emergency read-only remount is performed, detaching a log writer and synchronizing the filesystem can be done at the same time.
In these cases, use-after-free of the log writer (hereinafter nilfs->ns_writer) can happen as shown in the scenario below:
Task1 Task2 -------------------------------- ------------------------------ nilfs_construct_segment nilfs_segctor_sync init_wait init_waitqueue_entry add_wait_queue schedule nilfs_remount (R/W remount case) nilfs_attach_log_writer nilfs_detach_log_writer nilfs_segctor_destroy kfree finish_wait _raw_spin_lock_irqsave __raw_spin_lock_irqsave do_raw_spin_lock debug_spin_lock_before <-- use-after-free
While Task1 is sleeping, nilfs->ns_writer is freed by Task2. After Task1 waked up, Task1 accesses nilfs->ns_writer which is already freed. This scenario diagram is based on the Shigeru Yoshida's post [1].
This patch fixes the issue by not detaching nilfs->ns_writer on remount so that this UAF race doesn't happen. Along with this change, this patch also inserts a few necessary read-only checks with superblock instance where only the ns_writer pointer was used to check if the filesystem is read-only.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfo-common-x86_64Upgrade kernel-headersUpgrade python-perf-debuginfoUpgrade bpftool-debuginfoUpgrade perf-debuginfoUpgrade kernel-toolsUpgrade python-perfUpgrade kernel-livepatch-4.14.301-224.520Upgrade kernel-tools-develUpgrade kernelUpgrade perfUpgrade kernel-develUpgrade bpftoolUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-debuginfoUpgrade kernel-tools-debuginfoUpgrade kernel-livepatch-5.10.155-138.670 | Jun 23, 2025 | May 1, 2025 |
| Debian | — | Upgrade linux | May 5, 2025 | May 1, 2025 |
| Ubuntu | — | Upgrade linux-fipsUpgrade linux-gcp-5.4Upgrade linux-riscv-5.15Upgrade linux-ibm-5.4Upgrade linux-intel-iot-realtimeUpgrade linux-nvidiaUpgrade linux-oracle-5.4Upgrade linux-aws-hweUpgrade linux-aws-5.15Upgrade linux-intel-iotgUpgrade linux-nvidia-tegra-5.15Upgrade linux-gcpUpgrade linux-aws-5.4Upgrade linux-gkeUpgrade linux-xilinx-zynqmpUpgrade linux-lowlatencyUpgrade linux-oracleUpgrade linux-oracle-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-gkeopUpgrade linux-iotUpgrade linux-gcp-5.15Upgrade linux-gcp-4.15Upgrade linux-azure-5.4Upgrade linux-hwe-5.4Upgrade linux-aws-fipsUpgrade linux-realtimeUpgrade linux-azure-5.15Upgrade linux-awsUpgrade linux-azure-4.15Upgrade linux-gcp-fipsUpgrade linux-azure-fipsUpgrade linux-azureUpgrade linux-intel-iotg-5.15Upgrade linux-raspiUpgrade linux-hweUpgrade linux-ibmUpgrade linuxUpgrade linux-kvmUpgrade linux-hwe-5.15Upgrade linux-bluefieldUpgrade linux-raspi-5.4 | May 6, 2025 | May 1, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | May 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub