« Volver al listado

CVE-2023-54069

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ext4: fix BUG in ext4_mb_new_inode_pa() due to overflow

When we calculate the end position of ext4_free_extent, this position may be exactly where ext4_lblk_t (i.e. uint) overflows. For example, if ac_g_ex.fe_logical is 4294965248 and ac_orig_goal_len is 2048, then the computed end is 0x100000000, which is 0. If ac->ac_o_ex.fe_logical is not the first case of adjusting the best extent, that is, new_bex_end > 0, the following BUG_ON will be triggered:

A simple reproducer demonstrating the problem:

We simply refactor the logic for adjusting the best extent by adding a temporary ext4_free_extent ex and use extent_logical_end() to avoid overflow, which also simplifies the code.

Detalles técnicos trazas, registros y código del informe original
=========================================================
kernel BUG at fs/ext4/mballoc.c:5116!
invalid opcode: 0000 [#1] PREEMPT SMP PTI
CPU: 3 PID: 673 Comm: xfs_io Tainted: G E 6.5.0-rc1+ #279
RIP: 0010:ext4_mb_new_inode_pa+0xc5/0x430
Call Trace:
 <TASK>
 ext4_mb_use_best_found+0x203/0x2f0
 ext4_mb_try_best_found+0x163/0x240
 ext4_mb_regular_allocator+0x158/0x1550
 ext4_mb_new_blocks+0x86a/0xe10
 ext4_ext_map_blocks+0xb0c/0x13a0
 ext4_map_blocks+0x2cd/0x8f0
 ext4_iomap_begin+0x27b/0x400
 iomap_iter+0x222/0x3d0
 __iomap_dio_rw+0x243/0xcb0
 iomap_dio_rw+0x16/0x80
=========================================================

	mkfs.ext4 -F /dev/sda -b 4096 100M
	mount /dev/sda /tmp/test
	fallocate -l1M /tmp/test/tmp
	fallocate -l10M /tmp/test/file
	fallocate -i -o 1M -l16777203M /tmp/test/file
	fsstress -d /tmp/test -l 0 -n 100000 -p 8 &
	sleep 10 && killall -9 fsstress
	rm -f /tmp/test/tmp
	xfs_io -c "open -ad /tmp/test/file" -c "pwrite -S 0xff 0 8192"

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-54069",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "8659c5f4ffaacbe932849b98462c3d635b4eacea",
              "lessThan": "83ecffd40c65844a73c2e93d7c841455786605ac",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fc7237e191b99f88e859316fab2b06c2c26c8344",
              "lessThan": "58fe961c606c446f5612f6897827b1cac42c2e89",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "613f6cde5ebb005a37fda117cdda7b4126170c13",
              "lessThan": "f2c3a3aa6f11ad9878dbc3a067b0633e07b586c1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9d4430b7f862ce8835ca4e054b6916d15c8e0862",
              "lessThan": "fcefddf3a151b2c416b20120c06bb1ba9ad676fb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "93cdf49f6eca5e23f6546b8f28457b2e6a6961d9",
              "lessThan": "b7e9ec38b6a0beb5a49cd1e76be0a9a07c218e90",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "93cdf49f6eca5e23f6546b8f28457b2e6a6961d9",
              "lessThan": "bc056e7163ac7db945366de219745cf94f32a3e6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "46772ab99409cc72241227dd8f5295f358233fda",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "25a60b4533268477920faaeebd99e7e69c0735cd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cec4ef62b36b04e0bc8905732adab091f4bc1cfd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.4.244",
              "lessThan": "5.4.260",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.10.181",
              "lessThan": "5.10.200",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.113",
              "lessThan": "5.15.138",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.30",
              "lessThan": "6.1.61",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.14.316",
              "lessThan": "4.15",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.19.284",
              "lessThan": "4.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.3.4",
              "lessThan": "6.4",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/ext4/mballoc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.4"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.4",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.4.260",
              "versionType": "semver",
              "lessThanOrEqual": "5.4.*"
            },
            {
              "status": "unaffected",
              "version": "5.10.200",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.138",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.61",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.5.5",
              "versionType": "semver",
              "lessThanOrEqual": "6.5.*"
            },
            {
              "status": "unaffected",
              "version": "6.6",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/ext4/mballoc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-24T13:16:08.747",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/58fe961c606c446f5612f6897827b1cac42c2e89",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/83ecffd40c65844a73c2e93d7c841455786605ac",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b7e9ec38b6a0beb5a49cd1e76be0a9a07c218e90",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bc056e7163ac7db945366de219745cf94f32a3e6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f2c3a3aa6f11ad9878dbc3a067b0633e07b586c1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fcefddf3a151b2c416b20120c06bb1ba9ad676fb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix BUG in ext4_mb_new_inode_pa() due to overflow\n\nWhen we calculate the end position of ext4_free_extent, this position may\nbe exactly where ext4_lblk_t (i.e. uint) overflows. For example, if\nac_g_ex.fe_logical is 4294965248 and ac_orig_goal_len is 2048, then the\ncomputed end is 0x100000000, which is 0. If ac->ac_o_ex.fe_logical is not\nthe first case of adjusting the best extent, that is, new_bex_end > 0, the\nfollowing BUG_ON will be triggered:\n\n=========================================================\nkernel BUG at fs/ext4/mballoc.c:5116!\ninvalid opcode: 0000 [#1] PREEMPT SMP PTI\nCPU: 3 PID: 673 Comm: xfs_io Tainted: G E 6.5.0-rc1+ #279\nRIP: 0010:ext4_mb_new_inode_pa+0xc5/0x430\nCall Trace:\n <TASK>\n ext4_mb_use_best_found+0x203/0x2f0\n ext4_mb_try_best_found+0x163/0x240\n ext4_mb_regular_allocator+0x158/0x1550\n ext4_mb_new_blocks+0x86a/0xe10\n ext4_ext_map_blocks+0xb0c/0x13a0\n ext4_map_blocks+0x2cd/0x8f0\n ext4_iomap_begin+0x27b/0x400\n iomap_iter+0x222/0x3d0\n __iomap_dio_rw+0x243/0xcb0\n iomap_dio_rw+0x16/0x80\n=========================================================\n\nA simple reproducer demonstrating the problem:\n\n\tmkfs.ext4 -F /dev/sda -b 4096 100M\n\tmount /dev/sda /tmp/test\n\tfallocate -l1M /tmp/test/tmp\n\tfallocate -l10M /tmp/test/file\n\tfallocate -i -o 1M -l16777203M /tmp/test/file\n\tfsstress -d /tmp/test -l 0 -n 100000 -p 8 &\n\tsleep 10 && killall -9 fsstress\n\trm -f /tmp/test/tmp\n\txfs_io -c \"open -ad /tmp/test/file\" -c \"pwrite -S 0xff 0 8192\"\n\nWe simply refactor the logic for adjusting the best extent by adding\na temporary ext4_free_extent ex and use extent_logical_end() to avoid\noverflow, which also simplifies the code."
    }
  ],
  "lastModified": "2026-06-17T06:46:44.757",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}