CVE-2024-27070·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid use-after-free issue in f2fs_filemap_fault syzbot reports a f2fs bug as below: BUG: KASAN: slab-use-after-free in f2fs_filemap_fault+0xd1/0x2c0 fs/f2fs/file.c:49 Read of size 8 at addr ffff88807bb22680 by task syz-executor184/5058 CPU: 0 PID: 5058 Comm: syz-executor184 Not tainted 6.7.0-syzkaller-09928-g052d534373b7 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x1e7/0x2d0 lib/dump_stack.c:106 print_address_description mm/kasan/report.c:377 [inline] print_report+0x163/0x540 mm/kasan/report.c:488 kasan_report+0x142/0x170 mm/kasan/report.c:601 f2fs_filemap_fault+0xd1/0x2c0 fs/f2fs/file.c:49 __do_fault+0x131/0x450 mm/memory.c:4376 do_shared_fault mm/memory.c:4798 [inline] do_fault mm/memory.c:4872 [inline] do_pte_missing mm/memory.c:3745 [inline] handle_pte_fault mm/memory.c:5144 [inline] __handle_mm_fault+0x23b7/0x72b0 mm/memory.c:5285 handle_mm_fault+0x27e/0x770 mm/memory.c:5450 do_user_addr_fault arch/x86/mm/fault.c:1364 [inline] handle_page_fault arch/x86/mm/fault.c:1507 [inline] exc_page_fault+0x456/0x870 arch/x86/mm/fault.c:1563 asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:570 The root cause is: in f2fs_filemap_fault(), vmf->vma may be not alive after filemap_fault(), so it may cause use-after-free issue when accessing vmf->vma->vm_flags in trace_f2fs_filemap_fault(). So it needs to keep vm_flags in separated temporary variable for tracepoint use.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.8.2
- Published
- 2024-05-01
Affected versions
From: 6.8
Until: 6.8.2
Fixed in: 6.8.2
How to fix this CVE
Update your Linux kernel to version 6.8.2 or later to resolve a use-after-free condition in the F2FS filesystem's page fault handler. This vulnerability occurs when the virtual memory area (VMA) structure becomes freed while still being accessed during fault processing, potentially leading to memory corruption or denial of service. Apply the kernel update immediately on affected systems running kernel versions 6.8 through 6.8.1.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your kernel version with `uname -r` and verify if it falls in the range 6.8 to 6.8.1
- Step 2: Confirm F2FS filesystem usage with `mount | grep f2fs` to determine if this vulnerability applies to your storage configuration
- Step 3: Search system logs for KASAN errors using `grep -i 'f2fs_filemap_fault\|use-after-free' /var/log/kern.log /var/log/syslog` to detect potential exploitation attempts
- Step 4: After applying the patch, reboot the system and verify the new kernel version with `uname -r` to confirm version 6.8.2 or later is running
FAQ
What is CVE-2024-27070?
CVE-2024-27070 is a use-after-free vulnerability in the Linux kernel's F2FS filesystem implementation, specifically in the page fault handler. When a virtual memory area structure is deallocated while still being referenced during fault processing, it can lead to memory corruption or system instability.
Is CVE-2024-27070 being actively exploited?
No, CVE-2024-27070 is not listed as actively exploited by CISA and no public exploits are currently available. However, the vulnerability's high CVSS score of 7.8 warrants prompt patching.
What versions of Kernel are affected by CVE-2024-27070?
Linux kernel versions 6.8 through 6.8.1 are affected. The vulnerability has been resolved in kernel version 6.8.2 and later.
How do I check if my server is vulnerable to CVE-2024-27070?
Run `uname -r` to check your kernel version. If the output shows version 6.8.0 or 6.8.1, and your system uses F2FS filesystems (verify with `mount | grep f2fs`), your system is vulnerable.
Does Defensia detect CVE-2024-27070?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-27070 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/8186e16a766d709a08f188d2f4e84098f364bea1
- https://git.kernel.org/stable/c/897761d16564e899faecb9381b4818858705081f
- https://git.kernel.org/stable/c/eb70d5a6c932d9d23f4bb3e7b83782c21ac4b064
- https://git.kernel.org/stable/c/8186e16a766d709a08f188d2f4e84098f364bea1
- https://git.kernel.org/stable/c/eb70d5a6c932d9d23f4bb3e7b83782c21ac4b064
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-27070. Free for 1 server.
Get started free