nilfs2: fix potential use after free in nilfs_gccache_submit_read_data()
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential use after free in nilfs_gccache_submit_read_data() In nilfs_gccache_submit_read_data(), brelse(bh) is called to drop the reference count of bh when the call to nilfs_dat_translate() fails. If the reference count hits 0 and its owner page gets unlocked, bh may be freed. However, bh->b_page is dereferenced to put the page after that, which may result in a use-after-free bug. This patch moves the release operation after unlocking and putting the page. NOTE: The function in question is only called in GC, and in combination with current userland tools, address translation using DAT does not occur in that function, so the code path that causes this issue will not be executed. However, it is possible to run that code path by intentionally modifying the userland GC library or by calling the GC ioctl directly. [konishi.ryusuke@gmail.com: NOTE added to the commit log]
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-52566
Credits & Attribution
No credits recorded in the NVD database.
References
- https://git.kernel.org/stable/c/fb1084e63ee56958b0a56e17a50a4fd86445b9c1
- https://git.kernel.org/stable/c/bb61224f6abc8e71bfdf06d7c984e23460875f5b
- https://git.kernel.org/stable/c/193b5a1c6c67c36b430989dc063fe7ea4e200a33
- https://git.kernel.org/stable/c/7130a87ca32396eb9bf48b71a2d42259ae44c6c7
- https://git.kernel.org/stable/c/3936e8714907cd55e37c7cc50e50229e4a9042e8
- https://git.kernel.org/stable/c/980663f1d189eedafd18d80053d9cf3e2ceb5c8c
- https://git.kernel.org/stable/c/28df4646ad8b433340772edc90ca709cdefc53e2
- https://git.kernel.org/stable/c/7ee29facd8a9c5a26079148e36bcf07141b3a6bc
More from Linux
View All →Affected Vendor
Linux
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.