CVE-2024-26616·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: btrfs: scrub: avoid use-after-free when chunk length is not 64K aligned [BUG] There is a bug report that, on a ext4-converted btrfs, scrub leads to various problems, including: - "unable to find chunk map" errors BTRFS info (device vdb): scrub: started on devid 1 BTRFS critical (device vdb): unable to find chunk map for logical 2214744064 length 4096 BTRFS critical (device vdb): unable to find chunk map for logical 2214744064 length 45056 This would lead to unrepariable errors. - Use-after-free KASAN reports: ================================================================== BUG: KASAN: slab-use-after-free in __blk_rq_map_sg+0x18f/0x7c0 Read of size 8 at addr ffff8881013c9040 by task btrfs/909 CPU: 0 PID: 909 Comm: btrfs Not tainted 6.7.0-x64v3-dbg #11 c50636e9419a8354555555245df535e380563b2b Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 2023.11-2 12/24/2023 Call Trace: <TASK> dump_stack_lvl+0x43/0x60 print_report+0xcf/0x640 kasan_report+0xa6/0xd0 __blk_rq_map_sg+0x18f/0x7c0 virtblk_prep_rq.isra.0+0x215/0x6a0 [virtio_blk 19a65eeee9ae6fcf02edfad39bb9ddee07dcdaff] virtio_queue_rqs+0xc4/0x310 [virtio_blk 19a65eeee9ae6fcf02edfad39bb9ddee07dcdaff] blk_mq_flush_plug_list.part.0+0x780/0x860 __blk_flush_plug+0x1ba/0x220 blk_finish_plug+0x3b/0x60 submit_initial_group_read+0x10a/0x290 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965] flush_scrub_stripes+0x38e/0x430 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965] scrub_stripe+0x82a/0xae0 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965] scrub_chunk+0x178/0x200 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965] scrub_enumerate_chunks+0x4bc/0xa30 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965] btrfs_scrub_dev+0x398/0x810 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965] btrfs_ioctl+0x4b9/0x3020 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965] __x64_sys_ioctl+0xbd/0x100 do_syscall_64+0x5d/0xe0 entry_SYSCALL_64_after_hwframe+0x63/0x6b RIP: 0033:0x7f47e5e0952b - Crash, mostly due to above use-after-free [CAUSE] The converted fs has the following data chunk layout: item 2 key (FIRST_CHUNK_TREE CHUNK_ITEM 2214658048) itemoff 16025 itemsize 80 length 86016 owner 2 stripe_len 65536 type DATA|single For above logical bytenr 2214744064, it's at the chunk end (2214658048 + 86016 = 2214744064). This means btrfs_submit_bio() would split the bio, and trigger endio function for both of the two halves. However scrub_submit_initial_read() would only expect the endio function to be called once, not any more. This means the first endio function would already free the bbio::bio, leaving the bvec freed, thus the 2nd endio call would lead to use-after-free. [FIX] - Make sure scrub_read_endio() only updates bits in its range Since we may read less than 64K at the end of the chunk, we should not touch the bits beyond chunk boundary. - Make sure scrub_submit_initial_read() only to read the chunk range This is done by calculating the real number of sectors we need to read, and add sector-by-sector to the bio. Thankfully the scrub read repair path won't need extra fixes: - scrub_stripe_submit_repair_read() With above fixes, we won't update error bit for range beyond chunk, thus scrub_stripe_submit_repair_read() should never submit any read beyond the chunk.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.7.3
- Published
- 2024-03-11
Affected versions
From: 6.7
Until: 6.7.3
Fixed in: 6.7.3
How to fix this CVE
Update your Linux kernel to version 6.7.3 or later to resolve a critical use-after-free vulnerability in the Btrfs scrub subsystem that affects filesystems converted from ext4. This vulnerability can cause system crashes, memory corruption, and data integrity issues during scrub operations on non-64K-aligned chunks. Apply the kernel update immediately if you are running versions 6.7 through 6.7.2 with Btrfs.
sudo dnf update kernelDefensia detects this vulnerability
How to check if you are affected
- Check your kernel version: uname -r | grep -E '^6\.7\.[0-2]' to confirm if you are running a vulnerable version
- Verify if Btrfs is in use: df -t btrfs to identify Btrfs-formatted filesystems on your system
- Check if your Btrfs filesystem was converted from ext4: btrfs filesystem show to inspect filesystem metadata and conversion history
- Monitor kernel logs for scrub-related errors: grep -i 'scrub\|unable to find chunk map\|use-after-free' /var/log/kern.log to detect exploitation attempts or post-update confirmation
FAQ
What is CVE-2024-26616?
CVE-2024-26616 is a use-after-free vulnerability in the Linux kernel's Btrfs scrub mechanism that occurs when processing chunks with sizes not aligned to 64K boundaries, particularly on filesystems converted from ext4. This can lead to kernel crashes, memory corruption, and unrecoverable filesystem errors.
Is CVE-2024-26616 being actively exploited?
No, this vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploit code is available. However, exploitation may occur unknowingly during routine Btrfs scrub maintenance operations.
What versions of Kernel are affected by CVE-2024-26616?
Linux kernel versions 6.7.0 through 6.7.2 are vulnerable. The vulnerability is fixed in kernel version 6.7.3 and later.
How do I check if my server is vulnerable to CVE-2024-26616?
Run 'uname -r' to check your kernel version; if it shows 6.7.0, 6.7.1, or 6.7.2, you are vulnerable. Additionally, run 'df -t btrfs' to confirm if Btrfs is in use on your system.
Does Defensia detect CVE-2024-26616?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server running version 6.7.0-6.7.2, CVE-2024-26616 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/34de0f04684ec00c093a0455648be055f0e8e24f
- https://git.kernel.org/stable/c/642b9c520ef2f104277ad1f902f8526edbe087fb
- https://git.kernel.org/stable/c/f546c4282673497a06ecb6190b50ae7f6c85b02f
- https://git.kernel.org/stable/c/34de0f04684ec00c093a0455648be055f0e8e24f
- https://git.kernel.org/stable/c/642b9c520ef2f104277ad1f902f8526edbe087fb
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-26616. Free for 1 server.
Get started free