Wind River Support Network

HomeDefectsLIN1024-6303
Fixed

LIN1024-6303 : Security Advisory - linux - CVE-2024-56774

Created: Jan 8, 2025    Updated: Jan 9, 2025
Resolved Date: Jan 9, 2025
Found In Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

btrfs: add a sanity check for btrfs root in btrfs_search_slot()

Syzbot reports a null-ptr-deref in btrfs_search_slot().

The reproducer is using rescue=ibadroots, and the extent tree root is
corrupted thus the extent tree is NULL.

When scrub tries to search the extent tree to gather the needed extent
info, btrfs_search_slot() doesn't check if the target root is NULL or
not, resulting the null-ptr-deref.

Add sanity check for btrfs root before using it in btrfs_search_slot().

CREATE(Triage):(User=admin) CVE-2024-56774 (https://nvd.nist.gov/vuln/detail/CVE-2024-56774)

CVEs


Live chat
Online