CVE-2024-44941: f2fs: fix to cover read extent cache access with lock
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to cover read extent cache access with lock
syzbot reports a f2fs bug as below:
BUG: KASAN: slab-use-after-free in sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46
Read of size 4 at addr ffff8880739ab220 by task syz-executor200/5097
CPU: 0 PID: 5097 Comm: syz-executor200 Not tainted 6.9.0-rc6-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114
print_address_description mm/kasan/report.c:377 [inline]
print_report+0x169/0x550 mm/kasan/report.c:488
kasan_report+0x143/0x180 mm/kasan/report.c:601
sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46
do_read_inode fs/f2fs/inode.c:509 [inline]
f2fs_iget+0x33e1/0x46e0 fs/f2fs/inode.c:560
f2fs_nfs_get_inode+0x74/0x100 fs/f2fs/super.c:3237
generic_fh_to_dentry+0x9f/0xf0 fs/libfs.c:1413
exportfs_decode_fh_raw+0x152/0x5f0 fs/exportfs/expfs.c:444
exportfs_decode_fh+0x3c/0x80 fs/exportfs/expfs.c:584
do_handle_to_path fs/fhandle.c:155 [inline]
handle_to_path fs/fhandle.c:210 [inline]
do_handle_open+0x495/0x650 fs/fhandle.c:226
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
We missed to cover sanity_check_extent_cache() w/ extent cache lock,
so, below race case may happen, result in use after free issue.
- f2fs_iget
- do_read_inode
- f2fs_init_read_extent_tree
: add largest extent entry in to cache
- shrink
- f2fs_shrink_read_extent_tree
- __shrink_extent_tree
- __detach_extent_node
: drop largest extent entry
- sanity_check_extent_cache
: access et->largest w/o lock
let's refactor sanity_check_extent_cache() to avoid extent cache access
and call it before f2fs_init_read_extent_tree() to fix this issue.
Security readout for executives and security teams
Plain-English summary
CVE-2024-44941 is a Linux kernel bug in F2FS, the Flash-Friendly File System. A race condition can make the kernel read freed memory while loading an inode, causing a kernel memory-safety failure and likely system instability. The source bundle gives no CVSS score or confirmed real-world impact.
Executive priority
Treat this as a targeted kernel maintenance item, not an emergency based on current evidence. Patch during normal kernel update cycles, with higher priority for systems using F2FS or processing untrusted storage media.
Technical view
The issue is a use-after-free in F2FS extent cache handling. sanity_check_extent_cache() accessed read extent cache state without the required lock while another path could shrink and detach the largest extent entry. The fix refactors the check to avoid unlocked extent-cache access and calls it before initializing the read extent tree.
Likely exposure
Exposure is most likely on Linux systems that mount or process F2FS filesystems on affected kernel versions. The bundle does not prove remote reachability, privilege requirements, or whether common distributions shipped the vulnerable code unchanged.
Exploitation context
The report came from syzbot with a KASAN slab-use-after-free trace. The bundle marks KEV as false and provides no cited evidence of active exploitation, public exploit use, or weaponized attack paths.
Researcher notes
The available evidence supports a race-triggered memory-safety bug in fs/f2fs extent cache logic. Impact beyond kernel crash or instability is not established in the bundle. Do not assume remote exploitation, privilege escalation, or affected distro package ranges without vendor confirmation.
Mitigation direction
Apply Linux stable updates containing the referenced F2FS fixes.
Use your distribution's kernel advisory to identify the corrected package version.
Prioritize systems that mount F2FS filesystems or handle untrusted removable storage.
If no package fix is available, follow vendor kernel guidance before changing filesystem usage.
Validation and detection
Inventory Linux hosts and identify kernels with F2FS enabled or mounted.
Compare running kernel versions against vendor advisories and the referenced stable commits.
Check kernel changelogs for the F2FS extent cache locking fix.
Review crash logs for F2FS KASAN or use-after-free traces.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-44941 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.