U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-42105

Change History

New CVE Received from kernel.org 7/30/2024 4:15:03 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

nilfs2: fix inode number range checks

Patch series "nilfs2: fix potential issues related to reserved inodes".

This series fixes one use-after-free issue reported by syzbot, caused by
nilfs2's internal inode being exposed in the namespace on a corrupted
filesystem, and a couple of flaws that cause problems if the starting
number of non-reserved inodes written in the on-disk super block is
intentionally (or corruptly) changed from its default value.  


This patch (of 3):

In the current implementation of nilfs2, "nilfs->ns_first_ino", which
gives the first non-reserved inode number, is read from the superblock,
but its lower limit is not checked.

As a result, if a number that overlaps with the inode number range of
reserved inodes such as the root directory or metadata files is set in the
super block parameter, the inode number test macros (NILFS_MDT_INODE and
NILFS_VALID_INODE) will not function properly.

In addition, these test macros use left bit-shift calculations using with
the inode number as the shift count via the BIT macro, but the result of a
shift calculation that exceeds the bit width of an integer is undefined in
the C specification, so if "ns_first_ino" is set to a large value other
than the default value NILFS_USER_INO (=11), the macros may potentially
malfunction depending on the environment.

Fix these issues by checking the lower bound of "nilfs->ns_first_ino" and
by preventing bit shifts equal to or greater than the NILFS_USER_INO
constant in the inode number test macros.

Also, change the type of "ns_first_ino" from signed integer to unsigned
integer to avoid the need for type casting in comparisons such as the
lower bound check introduced this time.
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/08cab183a624ba71603f3754643ae11cab34dbc4 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/1c91058425a01131ea30dda6cf43c67b17884d6a [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/3be4dcc8d7bea52ea41f87aa4bbf959efe7a5987 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/57235c3c88bb430043728d0d02f44a4efe386476 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/731011ac6c37cbe97ece229fc6daa486276052c5 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/9194f8ca57527958bee207919458e372d638d783 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/e2fec219a36e0993642844be0f345513507031f4 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/fae1959d6ab2c52677b113935e36ab4e25df37ea [No types assigned]