{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-42300", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-07-30T07:40:12.270Z", "datePublished": "2024-08-17T09:09:07.311Z", "dateUpdated": "2026-08-05T11:36:29.855Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:36:29.855Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix race in z_erofs_get_gbuf()\n\nIn z_erofs_get_gbuf(), the current task may be migrated to another\nCPU between `z_erofs_gbuf_id()` and `spin_lock(&gbuf->lock)`.\n\nTherefore, z_erofs_put_gbuf() will trigger the following issue\nwhich was found by stress test:\n\n<2>[772156.434168] kernel BUG at fs/erofs/zutil.c:58!\n..\n<4>[772156.435007]\n<4>[772156.439237] CPU: 0 PID: 3078 Comm: stress Kdump: loaded Tainted: G E 6.10.0-rc7+ #2\n<4>[772156.439239] Hardware name: Alibaba Cloud Alibaba Cloud ECS, BIOS 1.0.0 01/01/2017\n<4>[772156.439241] pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n<4>[772156.439243] pc : z_erofs_put_gbuf+0x64/0x70 [erofs]\n<4>[772156.439252] lr : z_erofs_lz4_decompress+0x600/0x6a0 [erofs]\n..\n<6>[772156.445958] stress (3127): drop_caches: 1\n<4>[772156.446120] Call trace:\n<4>[772156.446121] z_erofs_put_gbuf+0x64/0x70 [erofs]\n<4>[772156.446761] z_erofs_lz4_decompress+0x600/0x6a0 [erofs]\n<4>[772156.446897] z_erofs_decompress_queue+0x740/0xa10 [erofs]\n<4>[772156.447036] z_erofs_runqueue+0x428/0x8c0 [erofs]\n<4>[772156.447160] z_erofs_readahead+0x224/0x390 [erofs]\n.." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerable code is reached through ordinary file reads/readahead on a mounted erofs filesystem (read(), mmap, page-fault paths), which requires local access to the system. There is no network-facing consumer of z_erofs_get_gbuf().\nAC:L - The attacker controls both sides of the race: it drives the decompression load (repeated reads plus cache eviction on compressed erofs files) and simultaneously forces the migration via sched_setaffinity() on its own reader threads or CPU oversubscription, and the bug was already shown to reproduce under a plain stress test.\nPR:L - Any unprivileged local user or sandboxed app that can read a file on an already-mounted erofs image reaches z_erofs_readahead → z_erofs_get_gbuf with no capability, LSM, or ownership check on the path; on Android every app reads compressed erofs system partitions by default.\nUI:N - The attacker triggers the decompression path entirely with its own reads on an already-mounted filesystem; no victim action such as mounting an image or opening a file is required.\nS:U - The corrupted spinlock state, the shared global buffer, and the resulting hang all reside within the kernel's own security authority, with no crossing into a hypervisor, IOMMU, or other security scope.\nC:H - The unbalanced spin_unlock() destroys mutual exclusion on the shared global decompression buffer, so one task's LZ4 decompression reads compressed bytes belonging to another task's file, placing content derived from files the attacker cannot otherwise read into its own page-cache pages; the same window also lets gbuf_growsize() vunmap a buffer still in use.\nI:H - Concurrent use of the same gbuf lets attacker-supplied compressed input be decompressed into the page cache pages of an unrelated inode, corrupting file data that other — including privileged — processes mmap and execute, and the vunmap-under-use window gives a write to freed/unmapped vmalloc memory.\nA:H - On CONFIG_EROFS_FS_DEBUG kernels this immediately panics at the DBG_BUGON in z_erofs_put_gbuf(); on production kernels the abandoned gbuf lock is never released, so every subsequent decompression mapping to it spins forever with preemption disabled, producing a hard lockup/RCU stall that requires a reboot." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/erofs/zutil.c" ], "versions": [ { "version": "f36f3010f67611a45d66e773bc91e4c66a9abab5", "lessThan": "49b22e06a947727a6d1c802d2d9ad92420b90fc5", "status": "affected", "versionType": "git" }, { "version": "f36f3010f67611a45d66e773bc91e4c66a9abab5", "lessThan": "7dc5537c3f8be87e005f0844a7626c987914f8fd", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/erofs/zutil.c" ], "versions": [ { "version": "6.10", "status": "affected" }, { "version": "0", "lessThan": "6.10", "status": "unaffected", "versionType": "semver" }, { "version": "6.10.3", "lessThanOrEqual": "6.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.11", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.10", "versionEndExcluding": "6.10.3" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.10", "versionEndExcluding": "6.11" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/49b22e06a947727a6d1c802d2d9ad92420b90fc5" }, { "url": "https://git.kernel.org/stable/c/7dc5537c3f8be87e005f0844a7626c987914f8fd" } ], "title": "erofs: fix race in z_erofs_get_gbuf()", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "id": "CVE-2024-42300", "role": "CISA Coordinator", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "version": "2.0.3", "timestamp": "2024-09-10T16:10:35.332066Z" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-09-12T17:33:28.436Z" } } ] } }