{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-35948","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-05-17T13:50:33.134Z","datePublished":"2024-05-20T09:17:34.536Z","dateUpdated":"2026-08-05T11:31:07.533Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:31:07.533Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbcachefs: Check for journal entries overruning end of sb clean section\n\nFix a missing bounds check in superblock validation.\n\nNote that we don't yet have repair code for this case - repair code for\nindividual items is generally low priority, since the whole superblock\nis checksummed, validated prior to write, and we have backups."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable code is reached only by mounting a bcachefs image (crafted USB stick, loop-mounted file, or removable media auto-mounted by udisks2), which requires local access to the machine. There is no network-facing path to the superblock clean-section parser.\nAC:L - The attacker fully controls every byte of the superblock, including the `jset_entry` u64s length field and the superblock checksum, so the overrun triggers deterministically on the first mount with no race or memory-layout precondition.\nPR:L - In the standard desktop/kiosk deployment an unprivileged local user need only attach the crafted volume and a root-owned auto-mounter parses it on their behalf, so no privileges beyond an ordinary local account are required to deliver the malicious superblock.\nUI:N - Under removable-media auto-mount the attacker inserts the device themselves and recovery runs without any separate victim action; no other user must open a file or perform any step.\nS:U - The out-of-bounds accesses corrupt and disclose kernel heap memory within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The unbounded walk reads up to ~512 KB past the kmemdup'd clean-section buffer, and the fsck error paths render those out-of-bounds heap bytes into the kernel log via `bch2_bkey_val_to_text()`, giving a direct heap-memory disclosure primitive.\nI:H - `journal_entry_null_range()` memsets and `journal_validate_key()` memmoves over memory past the end of the allocation, and the null-range loop advances by out-of-bounds `u64s` values with an `!=` terminator so it can overshoot and zero arbitrary adjacent heap objects — heap corruption exploitable for control-flow influence.\nA:H - The out-of-bounds read/write walk of up to hundreds of kilobytes past a small slab object reliably faults, trips KASAN/BUG, or corrupts unrelated kernel structures, panicking the machine on mount."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/bcachefs/sb-clean.c","fs/bcachefs/sb-errors_types.h"],"versions":[{"version":"1c6fdbd8f2465ddfb73a01ec620cbf3d14044e1a","lessThan":"fcdbc1d7a4b638e5d5668de461f320386f3002aa","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/bcachefs/sb-clean.c","fs/bcachefs/sb-errors_types.h"],"versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","status":"unaffected","versionType":"semver"},{"version":"6.9","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.9"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/fcdbc1d7a4b638e5d5668de461f320386f3002aa"}],"title":"bcachefs: Check for journal entries overruning end of sb clean section","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-400","lang":"en","description":"CWE-400 Uncontrolled Resource Consumption"}]}],"affected":[{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1da177e4c3f4","status":"affected","lessThan":"fcdbc1d7a4b6","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"unaffected","lessThanOrEqual":"6.9","versionType":"custom"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":8.4,"attackVector":"LOCAL","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2025-01-16T21:10:33.097520Z","id":"CVE-2024-35948","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-01-16T21:11:09.162Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T03:21:49.046Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/fcdbc1d7a4b638e5d5668de461f320386f3002aa","tags":["x_transferred"]}]}]}}