In the Linux kernel, the following vulnerability has been resolved:
ocfs2: fix uninitialized value in ocfs2fileread_iter()
Syzbot has reported the following KMSAN splat:
BUG: KMSAN: uninit-value in ocfs2filereaditer+0x9a4/0xf80 ocfs2filereaditer+0x9a4/0xf80 _ioread+0x8d4/0x20f0 ioread+0x3e/0xf0 ioissuesqe+0x42b/0x22c0 iowqsubmitwork+0xaf9/0xdc0 ioworkerhandlework+0xd13/0x2110 iowqworker+0x447/0x1410 retfromfork+0x6f/0x90 retfromforkasm+0x1a/0x30
Uninit was created at: allocpagesnoprof+0x9a7/0xe00 allocpagesmpolnoprof+0x299/0x990 allocpagesnoprof+0x1bf/0x1e0 allocateslab+0x33a/0x1250 slaballoc+0x12ef/0x35e0 kmemcacheallocbulknoprof+0x486/0x1330 _ioallocreqrefill+0x84/0x560 iosubmitsqes+0x172f/0x2f30 _sesysiouringenter+0x406/0x41c0 _x64sysiouringenter+0x11f/0x1a0 x64syscall+0x2b54/0x3ba0 dosyscall64+0xcd/0x1e0 entrySYSCALL64afterhwframe+0x77/0x7f
Since an instance of 'struct kiocb' may be passed from the block layer with 'private' field uninitialized, introduce 'ocfs2iocbinitrwlocked()' and use it from where 'ocfs2dioendio()' might take care, i.e. in 'ocfs2filereaditer()' and 'ocfs2filewrite_iter()'.
[
{
"id": "CVE-2024-53155-0e6ccfd9",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dc78efe556fed162d48736ef24066f42e463e27c",
"digest": {
"line_hashes": [
"287916876354516236450232482339327381746",
"88203561014090245761971939905610064653",
"329210928917156300196260389839371170308",
"132262399861728751146083783174325004417",
"310876137578300734232368965389334224659",
"239209911853106333021408818727748824639"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-1115f681",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/aops.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6c8f8d1e595dabd5389817f6d798cc8bd95c40ab",
"digest": {
"line_hashes": [
"107489723119660970335775774197687562408",
"273321220441737662678535353073250545854",
"310098605535169286072739435100417753297"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-1b6f3c33",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_read_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8e0de82ed18ba0e71f817adbd81317fd1032ca5a",
"digest": {
"length": 1170.0,
"function_hash": "32396524055791388814414252283424724416"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-1e670a07",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_read_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8c966150d5abff58c3c2bdb9a6e63fd773782905",
"digest": {
"length": 1170.0,
"function_hash": "32396524055791388814414252283424724416"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-218ef2a1",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_write_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@adc77b19f62d7e80f98400b2fca9d700d2afdd6f",
"digest": {
"length": 2417.0,
"function_hash": "135974004992216567394747627297330906035"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-23ab9f79",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/aops.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@83f8713a0ef1d55d6a287bcfadcaab8245ac5098",
"digest": {
"line_hashes": [
"107489723119660970335775774197687562408",
"273321220441737662678535353073250545854",
"310098605535169286072739435100417753297"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-28aa2d89",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@83f8713a0ef1d55d6a287bcfadcaab8245ac5098",
"digest": {
"line_hashes": [
"287916876354516236450232482339327381746",
"88203561014090245761971939905610064653",
"329210928917156300196260389839371170308",
"132262399861728751146083783174325004417",
"310876137578300734232368965389334224659",
"239209911853106333021408818727748824639"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-2f8b70eb",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@366c933c2ab34dd6551acc03b4872726b7605143",
"digest": {
"line_hashes": [
"287916876354516236450232482339327381746",
"88203561014090245761971939905610064653",
"329210928917156300196260389839371170308",
"132262399861728751146083783174325004417",
"310876137578300734232368965389334224659",
"239209911853106333021408818727748824639"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-337a6c89",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_write_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@66b7ddd1804e2c4216dd7ead8eeb746cdbb3b62f",
"digest": {
"length": 2417.0,
"function_hash": "135974004992216567394747627297330906035"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-347774cb",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_read_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@66b7ddd1804e2c4216dd7ead8eeb746cdbb3b62f",
"digest": {
"length": 1170.0,
"function_hash": "32396524055791388814414252283424724416"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-37d87378",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_read_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@adc77b19f62d7e80f98400b2fca9d700d2afdd6f",
"digest": {
"length": 1170.0,
"function_hash": "32396524055791388814414252283424724416"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-4064b2f1",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6c8f8d1e595dabd5389817f6d798cc8bd95c40ab",
"digest": {
"line_hashes": [
"287916876354516236450232482339327381746",
"88203561014090245761971939905610064653",
"329210928917156300196260389839371170308",
"132262399861728751146083783174325004417",
"310876137578300734232368965389334224659",
"239209911853106333021408818727748824639"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-491ad157",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_read_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@366c933c2ab34dd6551acc03b4872726b7605143",
"digest": {
"length": 1170.0,
"function_hash": "32396524055791388814414252283424724416"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-4d5b0f52",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/aops.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@66b7ddd1804e2c4216dd7ead8eeb746cdbb3b62f",
"digest": {
"line_hashes": [
"107489723119660970335775774197687562408",
"273321220441737662678535353073250545854",
"310098605535169286072739435100417753297"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-4dcaace8",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_write_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@83f8713a0ef1d55d6a287bcfadcaab8245ac5098",
"digest": {
"length": 2417.0,
"function_hash": "135974004992216567394747627297330906035"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-4e426e9c",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_read_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dc78efe556fed162d48736ef24066f42e463e27c",
"digest": {
"length": 1170.0,
"function_hash": "32396524055791388814414252283424724416"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-521b6e5a",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/aops.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@366c933c2ab34dd6551acc03b4872726b7605143",
"digest": {
"line_hashes": [
"107489723119660970335775774197687562408",
"273321220441737662678535353073250545854",
"310098605535169286072739435100417753297"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-6dc8e8e0",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/aops.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8e0de82ed18ba0e71f817adbd81317fd1032ca5a",
"digest": {
"line_hashes": [
"107489723119660970335775774197687562408",
"273321220441737662678535353073250545854",
"310098605535169286072739435100417753297"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-779f3200",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_write_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8e0de82ed18ba0e71f817adbd81317fd1032ca5a",
"digest": {
"length": 2417.0,
"function_hash": "135974004992216567394747627297330906035"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-7c3904bf",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_read_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6c8f8d1e595dabd5389817f6d798cc8bd95c40ab",
"digest": {
"length": 1170.0,
"function_hash": "32396524055791388814414252283424724416"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-7ceb021e",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@adc77b19f62d7e80f98400b2fca9d700d2afdd6f",
"digest": {
"line_hashes": [
"287916876354516236450232482339327381746",
"88203561014090245761971939905610064653",
"329210928917156300196260389839371170308",
"132262399861728751146083783174325004417",
"310876137578300734232368965389334224659",
"239209911853106333021408818727748824639"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-817f3cbe",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_write_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dc78efe556fed162d48736ef24066f42e463e27c",
"digest": {
"length": 2417.0,
"function_hash": "135974004992216567394747627297330906035"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-83d40565",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_read_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f4078ef38d3163e6be47403a619558b19c4bfccd",
"digest": {
"length": 1170.0,
"function_hash": "32396524055791388814414252283424724416"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-90d82789",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8c966150d5abff58c3c2bdb9a6e63fd773782905",
"digest": {
"line_hashes": [
"287916876354516236450232482339327381746",
"88203561014090245761971939905610064653",
"329210928917156300196260389839371170308",
"132262399861728751146083783174325004417",
"310876137578300734232368965389334224659",
"239209911853106333021408818727748824639"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-98180b0f",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@66b7ddd1804e2c4216dd7ead8eeb746cdbb3b62f",
"digest": {
"line_hashes": [
"287916876354516236450232482339327381746",
"88203561014090245761971939905610064653",
"329210928917156300196260389839371170308",
"132262399861728751146083783174325004417",
"310876137578300734232368965389334224659",
"239209911853106333021408818727748824639"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-ab2dddd1",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_write_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f4078ef38d3163e6be47403a619558b19c4bfccd",
"digest": {
"length": 2417.0,
"function_hash": "135974004992216567394747627297330906035"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-ab83812a",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/aops.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dc78efe556fed162d48736ef24066f42e463e27c",
"digest": {
"line_hashes": [
"107489723119660970335775774197687562408",
"273321220441737662678535353073250545854",
"310098605535169286072739435100417753297"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-af35792c",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/aops.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8c966150d5abff58c3c2bdb9a6e63fd773782905",
"digest": {
"line_hashes": [
"107489723119660970335775774197687562408",
"273321220441737662678535353073250545854",
"310098605535169286072739435100417753297"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-b5358bf0",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_write_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6c8f8d1e595dabd5389817f6d798cc8bd95c40ab",
"digest": {
"length": 2417.0,
"function_hash": "135974004992216567394747627297330906035"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-c7d59ba1",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/aops.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@adc77b19f62d7e80f98400b2fca9d700d2afdd6f",
"digest": {
"line_hashes": [
"107489723119660970335775774197687562408",
"273321220441737662678535353073250545854",
"310098605535169286072739435100417753297"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-c9b5ec76",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_write_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@366c933c2ab34dd6551acc03b4872726b7605143",
"digest": {
"length": 2417.0,
"function_hash": "135974004992216567394747627297330906035"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-cf765f6d",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/aops.h"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f4078ef38d3163e6be47403a619558b19c4bfccd",
"digest": {
"line_hashes": [
"107489723119660970335775774197687562408",
"273321220441737662678535353073250545854",
"310098605535169286072739435100417753297"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-f1992cef",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_write_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8c966150d5abff58c3c2bdb9a6e63fd773782905",
"digest": {
"length": 2417.0,
"function_hash": "135974004992216567394747627297330906035"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-f6042668",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8e0de82ed18ba0e71f817adbd81317fd1032ca5a",
"digest": {
"line_hashes": [
"287916876354516236450232482339327381746",
"88203561014090245761971939905610064653",
"329210928917156300196260389839371170308",
"132262399861728751146083783174325004417",
"310876137578300734232368965389334224659",
"239209911853106333021408818727748824639"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2024-53155-f7e175d5",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c",
"function": "ocfs2_file_read_iter"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@83f8713a0ef1d55d6a287bcfadcaab8245ac5098",
"digest": {
"length": 1170.0,
"function_hash": "32396524055791388814414252283424724416"
},
"signature_type": "Function"
},
{
"id": "CVE-2024-53155-fcfc2afe",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "fs/ocfs2/file.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f4078ef38d3163e6be47403a619558b19c4bfccd",
"digest": {
"line_hashes": [
"287916876354516236450232482339327381746",
"88203561014090245761971939905610064653",
"329210928917156300196260389839371170308",
"132262399861728751146083783174325004417",
"310876137578300734232368965389334224659",
"239209911853106333021408818727748824639"
],
"threshold": 0.9
},
"signature_type": "Line"
}
]