CVE-2024-27070: f2fs: fix to avoid use-after-free issue in f2fs_filemap_fault
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid use-after-free issue in f2fs_filemap_fault
syzbot reports a f2fs bug as below:
BUG: KASAN: slab-use-after-free in f2fs_filemap_fault+0xd1/0x2c0 fs/f2fs/file.c:49
Read of size 8 at addr ffff88807bb22680 by task syz-executor184/5058
CPU: 0 PID: 5058 Comm: syz-executor184 Not tainted 6.7.0-syzkaller-09928-g052d534373b7 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1e7/0x2d0 lib/dump_stack.c:106
print_address_description mm/kasan/report.c:377 [inline]
print_report+0x163/0x540 mm/kasan/report.c:488
kasan_report+0x142/0x170 mm/kasan/report.c:601
f2fs_filemap_fault+0xd1/0x2c0 fs/f2fs/file.c:49
__do_fault+0x131/0x450 mm/memory.c:4376
do_shared_fault mm/memory.c:4798 [inline]
do_fault mm/memory.c:4872 [inline]
do_pte_missing mm/memory.c:3745 [inline]
handle_pte_fault mm/memory.c:5144 [inline]
__handle_mm_fault+0x23b7/0x72b0 mm/memory.c:5285
handle_mm_fault+0x27e/0x770 mm/memory.c:5450
do_user_addr_fault arch/x86/mm/fault.c:1364 [inline]
handle_page_fault arch/x86/mm/fault.c:1507 [inline]
exc_page_fault+0x456/0x870 arch/x86/mm/fault.c:1563
asm_exc_page_fault+0x26/0x30 arch/x86/include/asm/idtentry.h:570
The root cause is: in f2fs_filemap_fault(), vmf->vma may be not alive after
filemap_fault(), so it may cause use-after-free issue when accessing
vmf->vma->vm_flags in trace_f2fs_filemap_fault(). So it needs to keep vm_flags
in separated temporary variable for tracepoint use.
Security readout for executives and security teams
Plain-English summary
A Linux kernel flaw in the F2FS filesystem can access memory after it has been freed during a file-backed page fault. A local, low-privileged user may be able to expose sensitive memory or crash an affected system. The supplied CVSS score is 7.1, high severity.
Executive priority
Prioritize normal high-severity patching, escalating systems that combine F2FS with untrusted local users. Internet-only exposure is not indicated. There is no supplied evidence of active exploitation, but confidentiality and availability impacts justify timely remediation.
Technical view
In f2fs_filemap_fault(), filemap_fault() may invalidate vmf->vma before trace_f2fs_filemap_fault() reads vmf->vma->vm_flags, causing a slab use-after-free. The stable fixes preserve vm_flags in a temporary variable before the potentially invalidating call. The issue was reproduced by syzbot with KASAN.
Likely exposure
Exposure requires an affected Linux kernel, use of F2FS, and local low-privileged access. Systems without F2FS usage are unlikely to reach this code path. The bundle lists affected 6.8-series kernel versions, but distribution-specific backports require vendor confirmation.
Exploitation context
The CVSS vector indicates local access, low complexity, low privileges, no user interaction, and potential high confidentiality and availability impact. The source bundle marks this CVE as absent from KEV and provides no evidence of active exploitation or a public exploit.
Researcher notes
The fault occurs after filemap_fault() may make vmf->vma unsafe to dereference. The fix snapshots vm_flags for later tracepoint use. The bundle provides no CWE, exploit evidence, or detailed distribution package mapping; affected status should therefore be verified against vendor advisories and backport records.
Mitigation direction
Install a vendor-supported kernel containing the referenced stable fix.
Prioritize multi-user systems where untrusted local users can access F2FS-backed files.
Consult distribution advisories to identify backported fixes and corrected package versions.
If immediate updating is impossible, reduce untrusted local access to systems using F2FS.
Validation and detection
Inventory running kernel versions and identify systems mounting or otherwise using F2FS.
Check vendor package changelogs for CVE-2024-27070 or the referenced stable commits.
After updating and rebooting, confirm the corrected kernel is running.
Review kernel crash and KASAN reports for f2fs_filemap_fault use-after-free signatures.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-27070 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.