Back

HIGH

bcache: fix variable length array abuse in btree_iter

Published Jul 5, 2024

Description

btree_iter is used in two ways: either allocated on the stack with a fixed size MAX_BSETS, or from a mempool with a dynamic size based on the specific cache set. Previously, the struct had a fixed-length array of size MAX_BSETS which was indexed out-of-bounds for the dynamically-sized iterators, which causes UBSAN to complain.

This patch uses the same approach as in bcachefs's sort_iter and splits the iterator into a btree_iter with a flexible array member and a btree_iter_stack which embeds a btree_iter as well as a fixed-length data array.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux is not vulnerable to this CVE, as it does not affect the versions or configurations of the Linux kernel used in its distributions.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jul 5, 2024
Updated Aug 5, 2026
Reserved Jun 25, 2024
CISA Vulnrichment
Updated Jul 8, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Jul 5, 2024
ENISA EUVD
Assigner Linux
Published Jul 5, 2024
Updated Aug 5, 2026
Exploited since n/a
EUVD-2024-38007