bcache: fix variable length array abuse in btree_iter
Published Jul 5, 2024
7.8
HIGHCVSS 3.1
EPSS 0.24%
Description
btree_iter is used in two ways: either allocated on the stack with a fixed size MAX_BSETS, or from a mempool with a dynamic size based on the specific cache set. Previously, the struct had a fixed-length array of size MAX_BSETS which was indexed out-of-bounds for the dynamically-sized iterators, which causes UBSAN to complain.
This patch uses the same approach as in bcachefs's sort_iter and splits the iterator into a btree_iter with a flexible array member and a btree_iter_stack which embeds a btree_iter as well as a fixed-length data array.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 3.10StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<3.10
- Version 5.10.221StatusunaffectedConstraints<=5.10.*
- Version 5.15.162StatusunaffectedConstraints<=5.15.*
- Version 6.1.94StatusunaffectedConstraints<=6.1.*
- Version 6.10StatusunaffectedConstraints<=*
- Version 6.6.34StatusunaffectedConstraints<=6.6.*
- Version 6.9.5StatusunaffectedConstraints<=6.9.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.10 · < 5.10.221
- ≥ 5.15 · < 5.15.162
- ≥ 6.1 · < 6.1.94
- ≥ 6.6 · < 6.6.34
- ≥ 6.9 · < 6.9.5
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux is not vulnerable to this CVE, as it does not affect the versions or configurations of the Linux kernel used in its distributions.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (15)
- https://access.redhat.com/security/cve/CVE-2024-39482 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2296054 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
- https://cert-portal.siemens.com/productcert/html/ssa-355557.html
- https://cert-portal.siemens.com/productcert/html/ssa-613116.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-38007 Advisory
- https://git.kernel.org/stable/c/0c31344e22dd8d6b1394c6e4c41d639015bdc671 Mailing ListPatch
- https://git.kernel.org/stable/c/2c3d7b03b658dc8bfa6112b194b67b92a87e081b Mailing ListPatch
- https://git.kernel.org/stable/c/3a861560ccb35f2a4f0a4b8207fa7c2a35fc7f31 Mailing ListPatch
- https://git.kernel.org/stable/c/5a1922adc5798b7ec894cd3f197afb6f9591b023 Mailing ListPatch
- https://git.kernel.org/stable/c/6479b9f41583b013041943c4602e1ad61cec8148 Mailing ListPatch
- https://git.kernel.org/stable/c/934e1e4331859183a861f396d7dfaf33cb5afb02 Mailing ListPatch
- https://lore.kernel.org/linux-cve-announce/2024070520-CVE-2024-39482-8ed3@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-39482
- https://www.cve.org/CVERecord?id=CVE-2024-39482
Change history (0)
No recorded changes yet.