{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-35798", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-05-17T12:19:12.341Z", "datePublished": "2024-05-17T13:23:08.868Z", "dateUpdated": "2026-08-05T11:30:01.532Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:30:01.532Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix race in read_extent_buffer_pages()\n\nThere are reports from tree-checker that detects corrupted nodes,\nwithout any obvious pattern so possibly an overwrite in memory.\nAfter some debugging it turns out there's a race when reading an extent\nbuffer the uptodate status can be missed.\n\nTo prevent concurrent reads for the same extent buffer,\nread_extent_buffer_pages() performs these checks:\n\n /* (1) */\n if (test_bit(EXTENT_BUFFER_UPTODATE, &eb->bflags))\n return 0;\n\n /* (2) */\n if (test_and_set_bit(EXTENT_BUFFER_READING, &eb->bflags))\n goto done;\n\nAt this point, it seems safe to start the actual read operation. Once\nthat completes, end_bbio_meta_read() does\n\n /* (3) */\n set_extent_buffer_uptodate(eb);\n\n /* (4) */\n clear_bit(EXTENT_BUFFER_READING, &eb->bflags);\n\nNormally, this is enough to ensure only one read happens, and all other\ncallers wait for it to finish before returning. Unfortunately, there is\na racey interleaving:\n\n Thread A | Thread B | Thread C\n ---------+----------+---------\n (1) | |\n | (1) |\n (2) | |\n (3) | |\n (4) | |\n | (2) |\n | | (1)\n\nWhen this happens, thread B kicks of an unnecessary read. Worse, thread\nC will see UPTODATE set and return immediately, while the read from\nthread B is still in progress. This race could result in tree-checker\nerrors like this as the extent buffer is concurrently modified:\n\n BTRFS critical (device dm-0): corrupted node, root=256\n block=8550954455682405139 owner mismatch, have 11858205567642294356\n expect [256, 18446744073709551360]\n\nFix it by testing UPTODATE again after setting the READING bit, and if\nit's been set, skip the unnecessary read.\n\n[ minor update of changelog ]" } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerable code is reached through ordinary filesystem syscalls (open/stat/read/readdir/write) against a locally mounted btrfs filesystem. No network protocol handler is involved, so this requires local system access.\nAC:L - The attacker controls every side of the race — multiple threads performing concurrent lookups of the same cold metadata block, with readahead supplying the WAIT_NONE submitter — and can retry indefinitely while adding memory and CPU pressure to widen the window. The race is known to trigger spontaneously in production without any attacker.\nPR:L - Any unprivileged local user with read access to a mounted btrfs filesystem can drive concurrent metadata reads of the same extent buffer; btrfs is the default root filesystem on several major distributions. No capability, ioctl, mount privilege, or namespace trick is needed.\nUI:N - The attacker triggers the race entirely with its own file I/O against an already-mounted filesystem. No victim action or cooperation is required.\nS:U - The corruption occurs within kernel memory and on-disk metadata managed by the same kernel security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - Threads consume extent-buffer contents while DMA concurrently overwrites them, yielding torn header/item fields; garbage node blockptrs and nritems drive reads of arbitrary logical addresses, and the resulting heap out-of-bounds access on struct btrfs_path is leverageable for kernel memory disclosure.\nI:H - btrfs_search_slot() writes p->nodes[level] and p->slots[level] with an unvalidated 8-bit level taken from the racing memory, giving an out-of-bounds write of a kernel pointer past a kmalloc'd btrfs_path; separately, a leaf modified under an in-flight overwrite is checksummed and written back, causing persistent on-disk metadata corruption.\nA:H - The documented outcome is tree-checker \"corrupted node\" reports leading to -EUCLEAN and transaction abort with the filesystem forced read-only, and the out-of-bounds writes and garbage tree traversal readily produce ASSERT/BUG_ON hits and kernel oopses." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/btrfs/extent_io.c" ], "versions": [ { "version": "d7172f52e9933b6ec9305e7fe6e829e3939dba04", "lessThan": "0427c8ef8bbb7f304de42ef51d69c960e165e052", "status": "affected", "versionType": "git" }, { "version": "d7172f52e9933b6ec9305e7fe6e829e3939dba04", "lessThan": "3a25878a3378adce5d846300c9570f15aa7f7a80", "status": "affected", "versionType": "git" }, { "version": "d7172f52e9933b6ec9305e7fe6e829e3939dba04", "lessThan": "2885d54af2c2e1d910e20d5c8045bae40e02fbc1", "status": "affected", "versionType": "git" }, { "version": "d7172f52e9933b6ec9305e7fe6e829e3939dba04", "lessThan": "ef1e68236b9153c27cb7cf29ead0c532870d4215", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/btrfs/extent_io.c" ], "versions": [ { "version": "6.5", "status": "affected" }, { "version": "0", "lessThan": "6.5", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.24", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.7.12", "lessThanOrEqual": "6.7.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.8.3", "lessThanOrEqual": "6.8.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.9", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.5", "versionEndExcluding": "6.6.24" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.5", "versionEndExcluding": "6.7.12" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.5", "versionEndExcluding": "6.8.3" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.5", "versionEndExcluding": "6.9" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/0427c8ef8bbb7f304de42ef51d69c960e165e052" }, { "url": "https://git.kernel.org/stable/c/3a25878a3378adce5d846300c9570f15aa7f7a80" }, { "url": "https://git.kernel.org/stable/c/2885d54af2c2e1d910e20d5c8045bae40e02fbc1" }, { "url": "https://git.kernel.org/stable/c/ef1e68236b9153c27cb7cf29ead0c532870d4215" } ], "title": "btrfs: fix race in read_extent_buffer_pages()", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2024-06-12T15:26:19.488238Z", "id": "CVE-2024-35798", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-06-12T15:26:30.636Z" } }, { "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T03:21:47.569Z" }, "title": "CVE Program Container", "references": [ { "url": "https://git.kernel.org/stable/c/0427c8ef8bbb7f304de42ef51d69c960e165e052", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/3a25878a3378adce5d846300c9570f15aa7f7a80", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/2885d54af2c2e1d910e20d5c8045bae40e02fbc1", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/ef1e68236b9153c27cb7cf29ead0c532870d4215", "tags": [ "x_transferred" ] } ] } ] } }