{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-35798","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-05-17T12:19:12.341Z","datePublished":"2024-05-17T13:23:08.868Z","dateUpdated":"2026-08-05T11:30:01.532Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:30:01.532Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix race in read_extent_buffer_pages()\n\nThere are reports from tree-checker that detects corrupted nodes,\nwithout any obvious pattern so possibly an overwrite in memory.\nAfter some debugging it turns out there's a race when reading an extent\nbuffer the uptodate status can be missed.\n\nTo prevent concurrent reads for the same extent buffer,\nread_extent_buffer_pages() performs these checks:\n\n    /* (1) */\n    if (test_bit(EXTENT_BUFFER_UPTODATE, &eb->bflags))\n        return 0;\n\n    /* (2) */\n    if (test_and_set_bit(EXTENT_BUFFER_READING, &eb->bflags))\n        goto done;\n\nAt this point, it seems safe to start the actual read operation. Once\nthat completes, end_bbio_meta_read() does\n\n    /* (3) */\n    set_extent_buffer_uptodate(eb);\n\n    /* (4) */\n    clear_bit(EXTENT_BUFFER_READING, &eb->bflags);\n\nNormally, this is enough to ensure only one read happens, and all other\ncallers wait for it to finish before returning.  Unfortunately, there is\na racey interleaving:\n\n    Thread A | Thread B | Thread C\n    ---------+----------+---------\n       (1)   |          |\n             |    (1)   |\n       (2)   |          |\n       (3)   |          |\n       (4)   |          |\n             |    (2)   |\n             |          |    (1)\n\nWhen this happens, thread B kicks of an unnecessary read. Worse, thread\nC will see UPTODATE set and return immediately, while the read from\nthread B is still in progress.  This race could result in tree-checker\nerrors like this as the extent buffer is concurrently modified:\n\n    BTRFS critical (device dm-0): corrupted node, root=256\n    block=8550954455682405139 owner mismatch, have 11858205567642294356\n    expect [256, 18446744073709551360]\n\nFix it by testing UPTODATE again after setting the READING bit, and if\nit's been set, skip the unnecessary read.\n\n[ minor update of changelog ]"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable code is reached through ordinary filesystem syscalls (open/stat/read/readdir/write) against a locally mounted btrfs filesystem. No network protocol handler is involved, so this requires local system access.\nAC:L - The attacker controls every side of the race — multiple threads performing concurrent lookups of the same cold metadata block, with readahead supplying the WAIT_NONE submitter — and can retry indefinitely while adding memory and CPU pressure to widen the window. The race is known to trigger spontaneously in production without any attacker.\nPR:L - Any unprivileged local user with read access to a mounted btrfs filesystem can drive concurrent metadata reads of the same extent buffer; btrfs is the default root filesystem on several major distributions. No capability, ioctl, mount privilege, or namespace trick is needed.\nUI:N - The attacker triggers the race entirely with its own file I/O against an already-mounted filesystem. No victim action or cooperation is required.\nS:U - The corruption occurs within kernel memory and on-disk metadata managed by the same kernel security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - Threads consume extent-buffer contents while DMA concurrently overwrites them, yielding torn header/item fields; garbage node blockptrs and nritems drive reads of arbitrary logical addresses, and the resulting heap out-of-bounds access on struct btrfs_path is leverageable for kernel memory disclosure.\nI:H - btrfs_search_slot() writes p->nodes[level] and p->slots[level] with an unvalidated 8-bit level taken from the racing memory, giving an out-of-bounds write of a kernel pointer past a kmalloc'd btrfs_path; separately, a leaf modified under an in-flight overwrite is checksummed and written back, causing persistent on-disk metadata corruption.\nA:H - The documented outcome is tree-checker \"corrupted node\" reports leading to -EUCLEAN and transaction abort with the filesystem forced read-only, and the out-of-bounds writes and garbage tree traversal readily produce ASSERT/BUG_ON hits and kernel oopses."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/btrfs/extent_io.c"],"versions":[{"version":"d7172f52e9933b6ec9305e7fe6e829e3939dba04","lessThan":"0427c8ef8bbb7f304de42ef51d69c960e165e052","status":"affected","versionType":"git"},{"version":"d7172f52e9933b6ec9305e7fe6e829e3939dba04","lessThan":"3a25878a3378adce5d846300c9570f15aa7f7a80","status":"affected","versionType":"git"},{"version":"d7172f52e9933b6ec9305e7fe6e829e3939dba04","lessThan":"2885d54af2c2e1d910e20d5c8045bae40e02fbc1","status":"affected","versionType":"git"},{"version":"d7172f52e9933b6ec9305e7fe6e829e3939dba04","lessThan":"ef1e68236b9153c27cb7cf29ead0c532870d4215","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/btrfs/extent_io.c"],"versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","status":"unaffected","versionType":"semver"},{"version":"6.6.24","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.7.12","lessThanOrEqual":"6.7.*","status":"unaffected","versionType":"semver"},{"version":"6.8.3","lessThanOrEqual":"6.8.*","status":"unaffected","versionType":"semver"},{"version":"6.9","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"6.6.24"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"6.7.12"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"6.8.3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"6.9"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/0427c8ef8bbb7f304de42ef51d69c960e165e052"},{"url":"https://git.kernel.org/stable/c/3a25878a3378adce5d846300c9570f15aa7f7a80"},{"url":"https://git.kernel.org/stable/c/2885d54af2c2e1d910e20d5c8045bae40e02fbc1"},{"url":"https://git.kernel.org/stable/c/ef1e68236b9153c27cb7cf29ead0c532870d4215"}],"title":"btrfs: fix race in read_extent_buffer_pages()","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-06-12T15:26:19.488238Z","id":"CVE-2024-35798","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-12T15:26:30.636Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T03:21:47.569Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/0427c8ef8bbb7f304de42ef51d69c960e165e052","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/3a25878a3378adce5d846300c9570f15aa7f7a80","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/2885d54af2c2e1d910e20d5c8045bae40e02fbc1","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/ef1e68236b9153c27cb7cf29ead0c532870d4215","tags":["x_transferred"]}]}]}}