f2fs: fix null-ptr-deref in f2fs_submit_page_bio()
Summary
| CVE | CVE-2024-53221 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-12-27 14:15:30 UTC |
| Updated | 2026-06-01 17:16:30 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix null-ptr-deref in f2fs_submit_page_bio() There's issue as follows when concurrently installing the f2fs.ko module and mounting the f2fs file system: KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027] RIP: 0010:__bio_alloc+0x2fb/0x6c0 [f2fs] Call Trace: <TASK> f2fs_submit_page_bio+0x126/0x8b0 [f2fs] __get_meta_page+0x1d4/0x920 [f2fs] get_checkpoint_version.constprop.0+0x2b/0x3c0 [f2fs] validate_checkpoint+0xac/0x290 [f2fs] f2fs_get_valid_checkpoint+0x207/0x950 [f2fs] f2fs_fill_super+0x1007/0x39b0 [f2fs] mount_bdev+0x183/0x250 legacy_get_tree+0xf4/0x1e0 vfs_get_tree+0x88/0x340 do_new_mount+0x283/0x5e0 path_mount+0x2b2/0x15b0 __x64_sys_mount+0x1fe/0x270 do_syscall_64+0x5f/0x170 entry_SYSCALL_64_after_hwframe+0x76/0x7e Above issue happens as the biset of the f2fs file system is not initialized before register "f2fs_fs_type". To address above issue just register "f2fs_fs_type" at the last in init_f2fs_fs(). Ensure that all f2fs file system resources are initialized. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-476
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected f543805fcd60f3f9a491cfa2f2dc9284d2569c28 4289be8465924748daa9bf14866eb7f0987d4e39 git | Not specified |
| CNA | Linux | Linux | affected f543805fcd60f3f9a491cfa2f2dc9284d2569c28 bd9197b72d772be7bccc3b66c83a3157cfe2f96f git | Not specified |
| CNA | Linux | Linux | affected f543805fcd60f3f9a491cfa2f2dc9284d2569c28 8dddc12d03248755d9f709bc1eb9e3ea2bf1b322 git | Not specified |
| CNA | Linux | Linux | affected f543805fcd60f3f9a491cfa2f2dc9284d2569c28 32f5e291b7677495f98246eec573767430321c08 git | Not specified |
| CNA | Linux | Linux | affected f543805fcd60f3f9a491cfa2f2dc9284d2569c28 9e11b1d5fda972f6be60ab732976a7c8e064cd56 git | Not specified |
| CNA | Linux | Linux | affected f543805fcd60f3f9a491cfa2f2dc9284d2569c28 b7d0a97b28083084ebdd8e5c6bccd12e6ec18faa git | Not specified |
| CNA | Linux | Linux | affected 5.6 | Not specified |
| CNA | Linux | Linux | unaffected 5.6 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.209 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.175 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.72 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.11.11 6.11.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.2 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.13 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/4289be8465924748daa9bf14866eb7f0987d4e39 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/32f5e291b7677495f98246eec573767430321c08 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/8dddc12d03248755d9f709bc1eb9e3ea2bf1b322 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b7d0a97b28083084ebdd8e5c6bccd12e6ec18faa | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/9e11b1d5fda972f6be60ab732976a7c8e064cd56 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/bd9197b72d772be7bccc3b66c83a3157cfe2f96f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.