CVE-2024-36027·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: do not flag ZEROOUT on non-dirty extent buffer Btrfs clears the content of an extent buffer marked as EXTENT_BUFFER_ZONED_ZEROOUT before the bio submission. This mechanism is introduced to prevent a write hole of an extent buffer, which is once allocated, marked dirty, but turns out unnecessary and cleaned up within one transaction operation. Currently, btrfs_clear_buffer_dirty() marks the extent buffer as EXTENT_BUFFER_ZONED_ZEROOUT, and skips the entry function. If this call happens while the buffer is under IO (with the WRITEBACK flag set, without the DIRTY flag), we can add the ZEROOUT flag and clear the buffer's content just before a bio submission. As a result: 1) it can lead to adding faulty delayed reference item which leads to a FS corrupted (EUCLEAN) error, and 2) it writes out cleared tree node on disk The former issue is previously discussed in [1]. The corruption happens when it runs a delayed reference update. So, on-disk data is safe. [1] https://lore.kernel.org/linux-btrfs/3f4f2a0ff1a6c818050434288925bdcf3cd719e5.1709124777.git.naohiro.aota@wdc.com/ The latter one can reach on-disk data. But, as that node is already processed by btrfs_clear_buffer_dirty(), that will be invalidated in the next transaction commit anyway. So, the chance of hitting the corruption is relatively small. Anyway, we should skip flagging ZEROOUT on a non-DIRTY extent buffer, to keep the content under IO intact.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.8.8
- Published
- 2024-05-30
Affected versions
From: 6.8
Until: 6.8.8
Fixed in: 6.8.8
How to fix this CVE
Update your Linux kernel to version 6.8.8 or later to resolve this btrfs zoned storage vulnerability. The fix prevents incorrect ZEROOUT flagging on extent buffers that are not dirty, which could lead to filesystem corruption or corrupted tree nodes being written to disk. Systems using btrfs on zoned block devices should prioritize this update.
sudo dnf update kernelDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your installed kernel version with `uname -r`. If the version is between 6.8 and 6.8.7 (inclusive), your system is vulnerable.
- Step 2: Verify if your system uses btrfs filesystem with `df -t btrfs`. If btrfs is present and mounted, the vulnerability is potentially exploitable.
- Step 3: Check for zoned block device support with `cat /sys/block/*/queue/zoned`. If any device shows 'host-managed' or 'host-aware', the system is using zoned storage.
- Step 4: After updating, confirm the new kernel version with `uname -r`. The version should be 6.8.8 or higher, and reboot if necessary with `sudo reboot`.
FAQ
What is CVE-2024-36027?
This vulnerability affects the Linux kernel's btrfs filesystem when operating with zoned block devices. An incorrect buffer state check allows the kernel to improperly flag extent buffers for zeroing operations even when they are actively being written to disk, potentially causing filesystem corruption or data inconsistency.
Is CVE-2024-36027 being actively exploited?
No, this vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and has no public exploits available. However, it can still cause unintended data corruption on affected systems.
What versions of Kernel are affected by CVE-2024-36027?
Linux kernel versions 6.8 through 6.8.7 are vulnerable. The fix is included in kernel 6.8.8 and all subsequent releases.
How do I check if my server is vulnerable to CVE-2024-36027?
Run `uname -r` to check your kernel version. If it displays a version between 6.8 and 6.8.7, and `df -t btrfs` shows active btrfs mounts, your system is vulnerable.
Does Defensia detect CVE-2024-36027?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-36027 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-36027. Free for 1 server.
Get started free