ext4: do not create EA inode under buffer lock
Published Jul 12, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.22%
Description
ext4_xattr_set_entry() creates new EA inodes while holding buffer lock on the external xattr block. This is problematic as it nests all the allocation locking (which acquires locks on other buffers) under the buffer lock. This can even deadlock when the filesystem is corrupted and e.g. quota file is setup to contain xattr block as data block. Move the allocation of EA inode out of ext4_xattr_set_entry() into the callers.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 4.13
Unaffected
- ≥ 0, < 4.13
- ≥ 6.1.107, ≤ 6.1.*
- 6.10
- ≥ 6.6.47, ≤ 6.6.*
- ≥ 6.9.7, ≤ 6.9.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- < 6.1.107
- ≥ 6.2 · < 6.6.47
- ≥ 6.7 · < 6.9.7
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.22.1.el8_10
Fixed · RHSA-2024:7000
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10
Fixed · RHSA-2024:7001
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.42.1.el9_4
Fixed · RHSA-2024:8617
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.42.1.el9_4
Fixed · RHSA-2024:8617
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.22.1.el8_10 | Fixed | RHSA-2024:7000 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10 | Fixed | RHSA-2024:7001 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.42.1.el9_4 | Fixed | RHSA-2024:8617 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.42.1.el9_4 | Fixed | RHSA-2024:8617 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (11)
- https://access.redhat.com/security/cve/CVE-2024-40972 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2297556 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-38769 Advisory
- https://git.kernel.org/stable/c/0752e7fb549d90c33b4d4186f11cfd25a556d1dd Patch
- https://git.kernel.org/stable/c/0a46ef234756dca04623b7591e8ebb3440622f0b Patch
- https://git.kernel.org/stable/c/111103907234bffd0a34fba070ad9367de058752 Patch
- https://git.kernel.org/stable/c/737fb7853acd5bc8984f6f42e4bfba3334be8ae1 Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://lore.kernel.org/linux-cve-announce/2024071229-CVE-2024-40972-1569@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-40972
- https://www.cve.org/CVERecord?id=CVE-2024-40972
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data