CVE-2024-40899·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: cachefiles: fix slab-use-after-free in cachefiles_ondemand_get_fd() We got the following issue in a fuzz test of randomly issuing the restore command: ================================================================== BUG: KASAN: slab-use-after-free in cachefiles_ondemand_daemon_read+0x609/0xab0 Write of size 4 at addr ffff888109164a80 by task ondemand-04-dae/4962 CPU: 11 PID: 4962 Comm: ondemand-04-dae Not tainted 6.8.0-rc7-dirty #542 Call Trace: kasan_report+0x94/0xc0 cachefiles_ondemand_daemon_read+0x609/0xab0 vfs_read+0x169/0xb50 ksys_read+0xf5/0x1e0 Allocated by task 626: __kmalloc+0x1df/0x4b0 cachefiles_ondemand_send_req+0x24d/0x690 cachefiles_create_tmpfile+0x249/0xb30 cachefiles_create_file+0x6f/0x140 cachefiles_look_up_object+0x29c/0xa60 cachefiles_lookup_cookie+0x37d/0xca0 fscache_cookie_state_machine+0x43c/0x1230 [...] Freed by task 626: kfree+0xf1/0x2c0 cachefiles_ondemand_send_req+0x568/0x690 cachefiles_create_tmpfile+0x249/0xb30 cachefiles_create_file+0x6f/0x140 cachefiles_look_up_object+0x29c/0xa60 cachefiles_lookup_cookie+0x37d/0xca0 fscache_cookie_state_machine+0x43c/0x1230 [...] ================================================================== Following is the process that triggers the issue: mount | daemon_thread1 | daemon_thread2 ------------------------------------------------------------ cachefiles_ondemand_init_object cachefiles_ondemand_send_req REQ_A = kzalloc(sizeof(*req) + data_len) wait_for_completion(&REQ_A->done) cachefiles_daemon_read cachefiles_ondemand_daemon_read REQ_A = cachefiles_ondemand_select_req cachefiles_ondemand_get_fd copy_to_user(_buffer, msg, n) process_open_req(REQ_A) ------ restore ------ cachefiles_ondemand_restore xas_for_each(&xas, req, ULONG_MAX) xas_set_mark(&xas, CACHEFILES_REQ_NEW); cachefiles_daemon_read cachefiles_ondemand_daemon_read REQ_A = cachefiles_ondemand_select_req write(devfd, ("copen %u,%llu", msg->msg_id, size)); cachefiles_ondemand_copen xa_erase(&cache->reqs, id) complete(&REQ_A->done) kfree(REQ_A) cachefiles_ondemand_get_fd(REQ_A) fd = get_unused_fd_flags file = anon_inode_getfile fd_install(fd, file) load = (void *)REQ_A->msg.data; load->fd = fd; // load UAF !!! This issue is caused by issuing a restore command when the daemon is still alive, which results in a request being processed multiple times thus triggering a UAF. So to avoid this problem, add an additional reference count to cachefiles_req, which is held while waiting and reading, and then released when the waiting and reading is over. Note that since there is only one reference count for waiting, we need to avoid the same request being completed multiple times, so we can only complete the request if it is successfully removed from the xarray.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.9.6
- Published
- 2024-07-12
Affected versions
From: 6.8
Until: 6.9.6
Fixed in: 6.9.6
How to fix this CVE
Update your Linux kernel to version 6.9.6 or later to resolve this use-after-free vulnerability in the cachefiles on-demand daemon. The fix introduces reference counting to prevent requests from being processed multiple times when restore commands are issued during daemon operation. Systems running kernel versions 6.8 through 6.9.5 should prioritize this patch immediately.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check kernel version with `uname -r` and verify if it falls in the 6.8 to 6.9.5 range
- Step 2: Verify cachefiles is enabled in your kernel configuration by checking if `/proc/fs/cachefiles` exists or running `grep -i cachefiles /boot/config-$(uname -r)`
- Step 3: Search for UAF-related kernel panic messages in logs with `sudo journalctl -xb | grep -i 'use-after-free\|kasan\|cachefiles'` or `sudo grep -i 'use-after-free' /var/log/kern.log`
- Step 4: After updating, reboot and run `uname -r` to confirm kernel version is 6.9.6 or later, then verify cachefiles still functions with `test -d /proc/fs/cachefiles && echo 'Cachefiles operational'`
FAQ
What is CVE-2024-40899?
CVE-2024-40899 is a use-after-free vulnerability in the Linux kernel's cachefiles on-demand daemon that occurs when restore commands are issued while the daemon is actively processing requests, causing memory corruption and potential system crash.
Is CVE-2024-40899 being actively exploited?
No, CVE-2024-40899 is not listed in CISA's Known Exploited Vulnerabilities catalog and has no public exploits available. However, it requires local access and affects systems using cachefiles, making it a moderate risk.
What versions of Kernel are affected by CVE-2024-40899?
Linux kernel versions 6.8.0 through 6.9.5 are affected. Version 6.9.6 and later contain the fix.
How do I check if my server is vulnerable to CVE-2024-40899?
Run `uname -r` to get your kernel version and compare against 6.8-6.9.5 range. Additionally, confirm cachefiles is active with `test -d /proc/fs/cachefiles && echo vulnerable || echo safe`.
Does Defensia detect CVE-2024-40899?
Yes — Defensia's CVE advisory scanner compares installed kernel package versions against the NVD database. If a vulnerable kernel version is detected on any monitored server, CVE-2024-40899 will appear in your dashboard with remediation steps and patch availability.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/1d902d9a3aa4f2a8bda698294e34be788be012fc
- https://git.kernel.org/stable/c/99e9c5bd27ddefa0f9db88625bf5e31c1e833d62
- https://git.kernel.org/stable/c/a6de82765e12fb1201ab607f0d3ffe3309b30fc0
- https://git.kernel.org/stable/c/de3e26f9e5b76fc628077578c001c4a51bf54d06
- https://git.kernel.org/stable/c/1d902d9a3aa4f2a8bda698294e34be788be012fc
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-40899. Free for 1 server.
Get started free