Tracker / CVE-2024-50006
CVE-2024-50006
In the Linux kernel, the following vulnerability has been resolved: ext4: fix i_data_sem unlock order in ext4_ind_migrate() Fuzzing reports a possible deadlock in jbd2_log_wait_commit. This issue is triggered when an EXT4_IOC_MIGRATE ioctl is set to require synchronous updates because the file descriptor is opened with O_SYNC. This can lead to the jbd2_journal_stop() function calling jbd2_might_wait_for_commit(), potentially causing a deadlock if the EXT4_IOC_MIGRATE call races with a write(2) system call. This problem only arises when CONFIG_PROVE_LOCKING is enabled. In this case, the jbd2_might_wait_for_commit macro locks jbd2_handle in the jbd2_journal_stop function while i_data_sem is locked. This triggers lockdep because the jbd2_journal_start function might also lock the same jbd2_handle simultaneously. Found by Linux Verification Center (linuxtesting.org) with syzkaller. Rule: add
Affected products and versions
| linux | linux_kernel · … → 5.10.227 |
|---|---|
| linux | linux_kernel · 5.11 → 5.15.168 |
| linux | linux_kernel · 5.16 → 6.1.113 |
| linux | linux_kernel · 6.11 → 6.11.3 |
| linux | linux_kernel · 6.2 → 6.6.55 |
| linux | linux_kernel · 6.7 → 6.10.14 |