jfs: check if leafidx greater than num leaves per dmap tree
Published Oct 21, 2024
7.8
HIGHCVSS 3.1
EPSS 0.29%
Description
syzbot report a out of bounds in dbSplit, it because dmt_leafidx greater than num leaves per dmap tree, add a checking for dmt_leafidx in dbFindLeaf.
Shaggy: Modified sanity check to apply to control pages as well as leaf pages.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 2.6.12
Unaffected
- ≥ 0, < 2.6.12
- ≥ 4.19.323, ≤ 4.19.*
- ≥ 5.10.227, ≤ 5.10.*
- ≥ 5.15.168, ≤ 5.15.*
- ≥ 5.4.285, ≤ 5.4.*
- ≥ 6.1.113, ≤ 6.1.*
- ≥ 6.10.14, ≤ 6.10.*
- ≥ 6.11.3, ≤ 6.11.*
- 6.12
- ≥ 6.6.55, ≤ 6.6.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
- < 5.10.227
- ≥ 5.11 · < 5.15.168
- ≥ 5.16 · < 6.1.113
- ≥ 6.2 · < 6.6.55
- ≥ 6.7 · < 6.10.14
- ≥ 6.11 · < 6.11.3
No data.
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
To mitigate this issue, prevent the `jfs` kernel module from loading if the JFS filesystem is not in use. This can be achieved by creating a modprobe configuration file. Create `/etc/modprobe.d/disable-jfs.conf` with the following content: `install jfs /bin/true` `blacklist jfs` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. `dracut -f -v` `reboot` This mitigation may impact systems that rely on the JFS filesystem.
References (19)
- https://access.redhat.com/security/cve/CVE-2024-49902 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320567 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
- https://cert-portal.siemens.com/productcert/html/ssa-355557.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-43598 Advisory
- https://git.kernel.org/stable/c/058aa89b3318be3d66a103ba7c68d717561e1dc6 Patch
- https://git.kernel.org/stable/c/2451e5917c56be45d4add786e2a059dd9c2c37c4 Patch
- https://git.kernel.org/stable/c/25d2a3ff02f22e215ce53355619df10cc5faa7ab Patch
- https://git.kernel.org/stable/c/35b91f15f44ce3c01eba058ccb864bb04743e792 Patch
- https://git.kernel.org/stable/c/4a7bf6a01fb441009a6698179a739957efd88e38 Patch
- https://git.kernel.org/stable/c/7fff9a9f866e99931cf6fa260288e55d01626582 Patch
- https://git.kernel.org/stable/c/cb0eb10558802764f07de1dc439c4609e27cb4f0 Patch
- https://git.kernel.org/stable/c/d64ff0d2306713ff084d4b09f84ed1a8c75ecc32 Patch
- https://git.kernel.org/stable/c/d76b9a4c283c7535ae7c7c9b14984e75402951e1 Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html
- https://lore.kernel.org/linux-cve-announce/2024102120-CVE-2024-49902-0b84@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-49902
- https://www.cve.org/CVERecord?id=CVE-2024-49902
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data