CVE-2024-27036·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix writeback data corruption cifs writeback doesn't correctly handle the case where cifs_extend_writeback() hits a point where it is considering an additional folio, but this would overrun the wsize - at which point it drops out of the xarray scanning loop and calls xas_pause(). The problem is that xas_pause() advances the loop counter - thereby skipping that page. What needs to happen is for xas_reset() to be called any time we decide we don't want to process the page we're looking at, but rather send the request we are building and start a new one. Fix this by copying and adapting the netfslib writepages code as a temporary measure, with cifs writeback intending to be offloaded to netfslib in the near future. This also fixes the issue with the use of filemap_get_folios_tag() causing retry of a bunch of pages which the extender already dealt with. This can be tested by creating, say, a 64K file somewhere not on cifs (otherwise copy-offload may get underfoot), mounting a cifs share with a wsize of 64000, copying the file to it and then comparing the original file and the copy: dd if=/dev/urandom of=/tmp/64K bs=64k count=1 mount //192.168.6.1/test /mnt -o user=...,pass=...,wsize=64000 cp /tmp/64K /mnt/64K cmp /tmp/64K /mnt/64K Without the fix, the cmp fails at position 64000 (or shortly thereafter).
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.8.2
- Published
- 2024-05-01
Affected versions
From: 6.8
Until: 6.8.2
Fixed in: 6.8.2
How to fix this CVE
Update your Linux kernel to version 6.8.2 or later to resolve a critical writeback data corruption issue in CIFS operations. This vulnerability causes file data to be corrupted when writing to CIFS-mounted shares with non-default wsize settings, requiring immediate patching to ensure data integrity.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your current kernel version with: uname -r (ensure it is NOT 6.8.0, 6.8.1, or 6.8.2 before the patch date)
- Step 2: Verify CIFS is mounted and in use by running: mount | grep cifs and checking if wsize is explicitly set
- Step 3: Test for data corruption on CIFS shares by comparing file checksums after writes: sha256sum /original/file && sha256sum /mnt/cifs/file
- Step 4: After applying the patch, reboot with: sudo reboot and verify new kernel with uname -r, then re-run checksum verification
FAQ
What is CVE-2024-27036?
CVE-2024-27036 is a writeback data corruption vulnerability in the Linux kernel's CIFS implementation where the xarray scanning loop incorrectly skips pages during large write operations, causing file data to be corrupted when transferred to CIFS-mounted shares.
Is CVE-2024-27036 being actively exploited?
No, this vulnerability is not listed in the CISA KEV catalog and has no publicly available exploits. However, it affects data integrity for any organization using CIFS mounts, making patching important for reliability rather than security response.
What versions of Kernel are affected by CVE-2024-27036?
Kernel versions 6.8.0, 6.8.1, and 6.8.2 (prior to the patch) are affected. The fix was released in kernel 6.8.2 and later versions.
How do I check if my server is vulnerable to CVE-2024-27036?
Run: uname -r to check your kernel version. If it reports 6.8.0, 6.8.1, or early 6.8.2, you are vulnerable. Additionally, check mount output with: mount | grep cifs to confirm CIFS usage.
Does Defensia detect CVE-2024-27036?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-27036 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/65f2ced695982ccd516196d0a9447d85dbe2eed5
- https://git.kernel.org/stable/c/844b4e132f57f1333dc79feaa035075a096762e4
- https://git.kernel.org/stable/c/e45deec35bf7f1f4f992a707b2d04a8c162f2240
- https://git.kernel.org/stable/c/f3dc1bdb6b0b0693562c7c54a6c28bafa608ba3c
- https://git.kernel.org/stable/c/65f2ced695982ccd516196d0a9447d85dbe2eed5
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-27036. Free for 1 server.
Get started free