f2fs: don't set RO when shutting down f2fs
Published Jul 12, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.22%
Description
Shutdown does not check the error of thaw_super due to readonly, which causes a deadlock like below.
f2fs_ioc_shutdown(F2FS_GOING_DOWN_FULLSYNC) issue_discard_thread - bdev_freeze - freeze_super - f2fs_stop_checkpoint() - f2fs_handle_critical_error - sb_start_write - set RO - waiting - bdev_thaw - thaw_super_locked - return -EINVAL, if sb_rdonly() - f2fs_stop_discard_thread -> wait for kthread_stop(discard_thread);
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 3.8StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<3.8
- Version 6.10StatusunaffectedConstraints<=*
- Version 6.6.36StatusunaffectedConstraints<=6.6.*
- Version 6.9.7StatusunaffectedConstraints<=6.9.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- < 6.6.36
- ≥ 6.7 · < 6.9.7
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux is not vulnerable to this CVE, as it does not affect the versions or configurations of the Linux kernel used in its distributions.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2024-40969 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2297553 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-38766 Advisory
- https://git.kernel.org/stable/c/1036d3ea7a32cb7cee00885c73a1f2ba7fbc499a Patch
- https://git.kernel.org/stable/c/3bdb7f161697e2d5123b89fe1778ef17a44858e7 Patch
- https://git.kernel.org/stable/c/f47ed3b284b38f235355e281f57dfa8fffcc6563 Patch
- https://lore.kernel.org/linux-cve-announce/2024071228-CVE-2024-40969-6507@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-40969
- https://www.cve.org/CVERecord?id=CVE-2024-40969
Change history (0)
No recorded changes yet.