xfs: add bounds checking to xlog_recover_process_data
Published Jul 29, 2024
7.1
HIGHCVSS 3.1
EPSS 0.24%
Description
There is a lack of verification of the space occupied by fixed members of xlog_op_header in the xlog_recover_process_data.
We can create a crafted image to trigger an out of bounds read by following these steps: 1) Mount an image of xfs, and do some file operations to leave records 2) Before umounting, copy the image for subsequent steps to simulate abnormal exit. Because umount will ensure that tail_blk and head_blk are the same, which will result in the inability to enter xlog_recover_process_data 3) Write a tool to parse and modify the copied image in step 2 4) Make the end of the xlog_op_header entries only 1 byte away from xlog_rec_header->h_size 5) xlog_rec_header->h_num_logops++ 6) Modify xlog_rec_header->h_crc
Fix: Add a check to make sure there is sufficient space to access fixed members of xlog_op_header.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.12StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.12
- Version 6.1.120StatusunaffectedConstraints<=6.1.*
- Version 6.11StatusunaffectedConstraints<=*
- Version 6.6.64StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- < 6.1.120
- ≥ 6.2 · < 6.6.64
- ≥ 6.7 · < 6.11
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.22.1.el8_10
Fixed · RHSA-2024:7000
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10
Fixed · RHSA-2024:7001
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
kernel-0:4.18.0-372.121.1.el8_6
Fixed · RHSA-2024:6297
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
kernel-0:4.18.0-372.121.1.el8_6
Fixed · RHSA-2024:6297
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
kernel-0:4.18.0-372.121.1.el8_6
Fixed · RHSA-2024:6297
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.81.1.el8_8
Fixed · RHSA-2024:10262
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.42.1.el9_4
Fixed · RHSA-2024:8617
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.42.1.el9_4
Fixed · RHSA-2024:8617
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.95.1.el9_2
Fixed · RHSA-2024:10772
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.95.1.rt14.380.el9_2
Fixed · RHSA-2024:10773
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.22.1.el8_10 | Fixed | RHSA-2024:7000 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10 | Fixed | RHSA-2024:7001 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.121.1.el8_6 | Fixed | RHSA-2024:6297 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | kernel-0:4.18.0-372.121.1.el8_6 | Fixed | RHSA-2024:6297 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | kernel-0:4.18.0-372.121.1.el8_6 | Fixed | RHSA-2024:6297 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.81.1.el8_8 | Fixed | RHSA-2024:10262 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.42.1.el9_4 | Fixed | RHSA-2024:8617 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.42.1.el9_4 | Fixed | RHSA-2024:8617 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.95.1.el9_2 | Fixed | RHSA-2024:10772 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.95.1.rt14.380.el9_2 | Fixed | RHSA-2024:10773 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2024-41014 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2300297 Issue Tracking
- https://git.kernel.org/stable/c/7cd9f0a33e738cd58876f1bc8d6c1aa5bc4fc8c1 Mailing ListPatch
- https://git.kernel.org/stable/c/d1e3efe783365db59da88f08a2e0bfe1cc95b143 Mailing ListPatch
- https://git.kernel.org/stable/c/fb63435b7c7dc112b1ae1baea5486e0a6e27b196 Mailing ListPatch
- https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html
- https://lore.kernel.org/linux-cve-announce/2024072910-CVE-2024-41014-9186@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-41014
- https://www.cve.org/CVERecord?id=CVE-2024-41014
Change history (0)
No recorded changes yet.