In the Linux kernel, the following vulnerability has been resolved:
ext4: fix slab-out-of-bounds in ext4_mb_find_good_group_avg_frag_lists()
We can trigger a slab-out-of-bounds with the following commands:
mkfs.ext4 -F /dev/$disk 10G mount /dev/$disk /tmp/test echo 2147483647 > /sys/fs/ext4/$disk/mb_group_prealloc echo test > /tmp/test/file && sync
================================================================== BUG: KASAN: slab-out-of-bounds in ext4_mb_find_good_group_avg_frag_lists+0x8a/0x200 [ext4] Read of size 8 at addr ffff888121b9d0f0 by task kworker/u2:0/11 CPU: 0 PID: 11 Comm: kworker/u2:0 Tainted: GL 6.7.0-next-20240118 #521 Call Trace: dump_stack_lvl+0x2c/0x50 kasan_report+0xb6/0xf0 ext4_mb_find_good_group_avg_frag_lists+0x8a/0x200 [ext4] ext4_mb_regular_allocator+0x19e9/0x2370 [ext4] ext4_mb_new_blocks+0x88a/0x1370 [ext4] ext4_ext_map_blocks+0x14f7/0x2390 [ext4] ext4_map_blocks+0x569/0xea0 [ext4] ext4_do_writepages+0x10f6/0x1bc0 [ext4] [...] ==================================================================
The flow of issue triggering is as follows:
// Set s_mb_group_prealloc to 2147483647 via sysfs ext4_mb_new_blocks ext4_mb_normalize_request ext4_mb_normalize_group_request ac->ac_g_ex.fe_len = EXT4_SB(sb)->s_mb_group_prealloc ext4_mb_regular_allocator ext4_mb_choose_next_group ext4_mb_choose_next_group_best_avail mb_avg_fragment_size_order order = fls(len) - 2 = 29 ext4_mb_find_good_group_avg_frag_lists frag_list = &sbi->s_mb_avg_fragment_size[order] if (list_empty(frag_list)) // Trigger SOOB!
At 4k block size, the length of the s_mb_avg_fragment_size list is 14, but an oversized s_mb_group_prealloc is set, causing slab-out-of-bounds to be triggered by an attempt to access an element at index 29.
Add a new attr_id attr_clusters_in_group with values in the range [0, sbi->s_clusters_per_group] and declare mb_group_prealloc as that type to fix the issue. In addition avoid returning an order from mb_avg_fragment_size_order() greater than MB_NUM_ORDERS(sb) and reduce some useless loops.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 12, 2024 |
| Ubuntu | — | Upgrade linux-image-6.8.0-1013-nvidia-lowlatencyUpgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-6.8.0-44-lowlatencyUpgrade linux-image-6.8.0-1012-oracle-64kUpgrade linux-image-6.8.0-1012-oracleUpgrade linux-image-oem-22.04dUpgrade linux-image-6.8.0-1010-gkeUpgrade linux-image-lowlatency-64kUpgrade linux-image-oem-22.04Upgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-generic-lpaeUpgrade linux-image-nvidia-64k-6.8Upgrade linux-image-azureUpgrade linux-image-nvidia-lowlatencyUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-awsUpgrade linux-image-6.8.0-1014-gcpUpgrade linux-image-6.8.0-1012-ibmUpgrade linux-image-azure-fdeUpgrade linux-image-raspiUpgrade linux-image-nvidia-6.8Upgrade linux-image-6.8.0-44-generic-64kUpgrade linux-image-6.8.0-1015-awsUpgrade linux-image-6.8.0-45-genericUpgrade linux-image-6.8.0-1013-nvidiaUpgrade linux-image-oem-22.04bUpgrade linux-image-6.8.0-1013-nvidia-lowlatency-64kUpgrade linux-image-ibm-classicUpgrade linux-image-6.8.0-1014-azure-fdeUpgrade linux-image-generic-hwe-22.04Upgrade linux-image-virtual-hwe-24.04Upgrade linux-image-oracle-64kUpgrade linux-image-ibmUpgrade linux-image-generic-64kUpgrade linux-image-oracleUpgrade linux-image-6.8.0-44-lowlatency-64kUpgrade linux-image-nvidia-64kUpgrade linux-image-lowlatencyUpgrade linux-image-6.8.0-44-genericUpgrade linux-image-6.8.0-1013-nvidia-64kUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-6.8.0-45-generic-64kUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-virtualUpgrade linux-image-oem-22.04aUpgrade linux-image-genericUpgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-6.8.0-1012-oemUpgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-6.8.0-1011-raspiUpgrade linux-image-gcpUpgrade linux-image-nvidiaUpgrade linux-image-kvmUpgrade linux-image-virtual-hwe-22.04Upgrade linux-image-oem-22.04cUpgrade linux-image-6.8.0-1014-azureUpgrade linux-image-gke | Sep 12, 2024 | Jul 12, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub