f2fs: compress: fix to avoid use-after-free on dic
Published May 21, 2024
7.8
HIGHCVSS 3.1
EPSS 0.24%
Description
Call trace: __memcpy+0x128/0x250 f2fs_read_multi_pages+0x940/0xf7c f2fs_mpage_readpages+0x5a8/0x624 f2fs_readahead+0x5c/0x110 page_cache_ra_unbounded+0x1b8/0x590 do_sync_mmap_readahead+0x1dc/0x2e4 filemap_fault+0x254/0xa8c f2fs_filemap_fault+0x2c/0x104 __do_fault+0x7c/0x238 do_handle_mm_fault+0x11bc/0x2d14 do_mem_abort+0x3a8/0x1004 el0_da+0x3c/0xa0 el0t_64_sync_handler+0xc4/0xec el0t_64_sync+0x1b4/0x1b8
In f2fs_read_multi_pages(), once f2fs_decompress_cluster() was called if we hit cached page in compress_inode's cache, dic may be released, it needs break the loop rather than continuing it, in order to avoid accessing invalid dic pointer.
Affected products
-
- Version 5.13.19StatusaffectedConstraints<5.14
- Version
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version
-
- Version 5.14StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.14
- Version 5.15.139StatusunaffectedConstraints<=5.15.*
- Version 6.1.63StatusunaffectedConstraints<=6.1.*
- Version 6.5.12StatusunaffectedConstraints<=6.5.*
- Version 6.6.2StatusunaffectedConstraints<=6.6.*
- Version 6.7StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.13.19 · < 5.15.139
- ≥ 5.16 · < 6.1.63
- ≥ 6.2 · < 6.5.12
- ≥ 6.6 · < 6.6.2
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2023-52852 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2282747 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59565 Advisory
- https://git.kernel.org/stable/c/8c4504cc0c64862740a6acb301e0cfa59580dbc5 Patch
- https://git.kernel.org/stable/c/932ddb5c29e884cc6fac20417ece72ba4a35c401 Patch
- https://git.kernel.org/stable/c/9375ea7f269093d7c884857ae1f47633a91f429c Patch
- https://git.kernel.org/stable/c/9d065aa52b6ee1b06f9c4eca881c9b4425a12ba2 Patch
- https://git.kernel.org/stable/c/b0327c84e91a0f4f0abced8cb83ec86a7083f086 Patch
- https://lore.kernel.org/linux-cve-announce/2024052114-CVE-2023-52852-e55a@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-52852
- https://www.cve.org/CVERecord?id=CVE-2023-52852
Change history (0)
No recorded changes yet.