{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-42111","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-07-29T15:50:41.176Z","datePublished":"2024-07-30T07:46:05.570Z","dateUpdated":"2026-08-05T11:35:43.268Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:35:43.268Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: always do the basic checks for btrfs_qgroup_inherit structure\n\n[BUG]\nSyzbot reports the following regression detected by KASAN:\n\n  BUG: KASAN: slab-out-of-bounds in btrfs_qgroup_inherit+0x42e/0x2e20 fs/btrfs/qgroup.c:3277\n  Read of size 8 at addr ffff88814628ca50 by task syz-executor318/5171\n\n  CPU: 0 PID: 5171 Comm: syz-executor318 Not tainted 6.10.0-rc2-syzkaller-00010-g2ab795141095 #0\n  Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/02/2024\n  Call Trace:\n   <TASK>\n   __dump_stack lib/dump_stack.c:88 [inline]\n   dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114\n   print_address_description mm/kasan/report.c:377 [inline]\n   print_report+0x169/0x550 mm/kasan/report.c:488\n   kasan_report+0x143/0x180 mm/kasan/report.c:601\n   btrfs_qgroup_inherit+0x42e/0x2e20 fs/btrfs/qgroup.c:3277\n   create_pending_snapshot+0x1359/0x29b0 fs/btrfs/transaction.c:1854\n   create_pending_snapshots+0x195/0x1d0 fs/btrfs/transaction.c:1922\n   btrfs_commit_transaction+0xf20/0x3740 fs/btrfs/transaction.c:2382\n   create_snapshot+0x6a1/0x9e0 fs/btrfs/ioctl.c:875\n   btrfs_mksubvol+0x58f/0x710 fs/btrfs/ioctl.c:1029\n   btrfs_mksnapshot+0xb5/0xf0 fs/btrfs/ioctl.c:1075\n   __btrfs_ioctl_snap_create+0x387/0x4b0 fs/btrfs/ioctl.c:1340\n   btrfs_ioctl_snap_create_v2+0x1f2/0x3a0 fs/btrfs/ioctl.c:1422\n   btrfs_ioctl+0x99e/0xc60\n   vfs_ioctl fs/ioctl.c:51 [inline]\n   __do_sys_ioctl fs/ioctl.c:907 [inline]\n   __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:893\n   do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n   do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n  RIP: 0033:0x7fcbf1992509\n  RSP: 002b:00007fcbf1928218 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\n  RAX: ffffffffffffffda RBX: 00007fcbf1a1f618 RCX: 00007fcbf1992509\n  RDX: 0000000020000280 RSI: 0000000050009417 RDI: 0000000000000003\n  RBP: 00007fcbf1a1f610 R08: 00007ffea1298e97 R09: 0000000000000000\n  R10: 0000000000000000 R11: 0000000000000246 R12: 00007fcbf19eb660\n  R13: 00000000200002b8 R14: 00007fcbf19e60c0 R15: 0030656c69662f2e\n   </TASK>\n\nAnd it also pinned it down to commit b5357cb268c4 (\"btrfs: qgroup: do not\ncheck qgroup inherit if qgroup is disabled\").\n\n[CAUSE]\nThat offending commit skips the whole qgroup inherit check if qgroup is\nnot enabled.\n\nBut that also skips the very basic checks like\nnum_ref_copies/num_excl_copies and the structure size checks.\n\nMeaning if a qgroup enable/disable race is happening at the background,\nand we pass a btrfs_qgroup_inherit structure when the qgroup is\ndisabled, the check would be completely skipped.\n\nThen at the time of transaction commitment, qgroup is re-enabled and\nbtrfs_qgroup_inherit() is going to use the incorrect structure and\ncausing the above KASAN error.\n\n[FIX]\nMake btrfs_qgroup_check_inherit() only skip the source qgroup checks.\nSo that even if invalid btrfs_qgroup_inherit structure is passed in, we\ncan still reject invalid ones no matter if qgroup is enabled or not.\n\nFurthermore we do already have an extra safety inside\nbtrfs_qgroup_inherit(), which would just ignore invalid qgroup sources,\nso even if we only skip the qgroup source check we're still safe."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerability is reached through the BTRFS_IOC_SNAP_CREATE_V2/BTRFS_IOC_SUBVOL_CREATE_V2 ioctls on a mounted btrfs filesystem, requiring a local account on the system. There is no network-facing path to this code.\nAC:L - The attacker fully controls the malformed btrfs_qgroup_inherit structure and the long side of the check-to-use window, which spans an entire transaction commit and can be stretched with I/O load, and the snapshot ioctl can be replayed in a tight loop indefinitely until the window is hit. No memory layout or timing condition outside the attacker's influence is needed to trigger the out-of-bounds access itself.\nPR:L - Issuing the vulnerable ioctl requires no capability at all - subvolume creation is explicitly unrestricted and snapshot creation only requires ownership of one's own subvolume, so an ordinary unprivileged user with write access to a btrfs directory suffices. The concurrent qgroup enable is background system activity (snapper, container/LXD tooling), not a privilege the attacker must hold.\nUI:N - The attack is driven entirely by the attacker's own ioctl calls against an already-mounted btrfs filesystem. No victim action is required.\nS:U - The out-of-bounds access corrupts kernel slab memory within the same kernel security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - The loop performs an unbounded sequential out-of-bounds read of kernel slab memory past a buffer of attacker-chosen size, with the read length controlled by the unvalidated num_qgroups/num_ref_copies/num_excl_copies fields. Read values that match existing qgroup IDs escape zeroing and are propagated into qgroup relations, and the corrupted adjacent objects provide a route to broader kernel memory disclosure.\nI:H - The same loop performs an out-of-bounds write (*i_qgroups = 0ULL) into memory following the slab object, with both the target slab size class (via vol_args->size) and the corruption length attacker-controlled. Zeroing pointers, refcounts, and length fields in groomed neighbouring objects is a well-established path to use-after-free and privilege escalation.\nA:H - Syzbot reproduced this as a KASAN slab-out-of-bounds, and a large attacker-supplied count walks the loop into unmapped memory or destroys adjacent kernel structures, producing an oops or panic. The corruption also occurs during transaction commit, where failures escalate to a filesystem abort."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/btrfs/qgroup.c"],"versions":[{"version":"b5357cb268c41b4e2b7383d2759fc562f5b58c33","lessThan":"ebe5ea02577b2c527958af1b76ac472c7ab53a56","status":"affected","versionType":"git"},{"version":"b5357cb268c41b4e2b7383d2759fc562f5b58c33","lessThan":"724d8042cef84496ddb4492dc120291f997ae26b","status":"affected","versionType":"git"},{"version":"c839f73a70f312f477225b64020364e108f08231","status":"affected","versionType":"git"},{"version":"6.8.10","lessThan":"6.9","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/btrfs/qgroup.c"],"versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","status":"unaffected","versionType":"semver"},{"version":"6.9.9","lessThanOrEqual":"6.9.*","status":"unaffected","versionType":"semver"},{"version":"6.10","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"6.9.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"6.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8.10"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ebe5ea02577b2c527958af1b76ac472c7ab53a56"},{"url":"https://git.kernel.org/stable/c/724d8042cef84496ddb4492dc120291f997ae26b"}],"title":"btrfs: always do the basic checks for btrfs_qgroup_inherit structure","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T04:54:32.553Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/ebe5ea02577b2c527958af1b76ac472c7ab53a56","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/724d8042cef84496ddb4492dc120291f997ae26b","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-42111","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-09-10T16:17:29.663997Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-11T17:33:06.663Z"}}]}}