CVE-2023-54068
Last modified
CVE-2023-54068 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages() BUG_ON() will be triggered when writing files concurrently, because the same page is writtenback multiple times. 1597 void folio_end_writeback(struct folio *folio) 1598 { ...... 1618 if (!__folio_end_writeback(folio)) 1619 BUG(); ...... 1625 } kernel BUG at mm/filemap.c:1619! Call Trace: <TASK> f2fs_write_end_io+0x1a0/0x370 blk_update_request+0x6c/0x410 blk_mq_end_request+0x15/0x130 blk_complete_reqs+0x3c/0x50 __do_softirq+0xb8/0x29b ? sort_range+0x20/0x20 run_ksoftirqd+0x19/0x20 smpboot_thread_fn+0x10b/0x1d0 kthread+0xde/0x110 ? kthread_complete_and_exit+0x20/0x20 ret_from_fork+0x22/0x30 </TASK> Below is the concurrency scenario: [Process A] [Process B] [Process C] f2fs_write_raw_pages() - redirty_page_for_writepage() - unlock page() f2fs_do_write_data_page() - lock_page() - clear_page_dirty_for_io() - set_page_writeback() [1st writeback] ..... - unlock page() generic_perform_write() - f2fs_write_begin() - wait_for_stable_page() - f2fs_write_end() - set_page_dirty() - lock_page() - f2fs_do_write_data_page() - set_page_writeback() [2st writeback] This problem was introduced by the previous commit 7377e853967b ("f2fs: compress: fix potential deadlock of compress file"). All pagelocks were released in f2fs_write_raw_pages(), but whether the page was in the writeback state was ignored in the subsequent writing process. Let's fix it by waiting for the page to writeback before writing.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages() BUG_ON() will be triggered when writing files concurrently, because the same page is writtenback multiple times. 1597 void folio_end_writeback(struct folio *folio) 1598 { ...... 1618 if (!__folio_end_writeback(folio)) 1619 BUG(); ...... 1625 } kernel BUG at mm/filemap.c:1619! Call Trace: <TASK> f2fs_write_end_io+0x1a0/0x370 blk_update_request+0x6c/0x410 blk_mq_end_request+0x15/0x130 blk_complete_reqs+0x3c/0x50 __do_softirq+0xb8/0x29b ? sort_range+0x20/0x20 run_ksoftirqd+0x19/0x20 smpboot_thread_fn+0x10b/0x1d0 kthread+0xde/0x110 ? kthread_complete_and_exit+0x20/0x20 ret_from_fork+0x22/0x30 </TASK> Below is the concurrency scenario: [Process A] [Process B] [Process C] f2fs_write_raw_pages() - redirty_page_for_writepage() - unlock page() f2fs_do_write_data_page() - lock_page() - clear_page_dirty_for_io() - set_page_writeback() [1st writeback] ..... - unlock page() generic_perform_write() - f2fs_write_begin() - wait_for_stable_page() - f2fs_write_end() - set_page_dirty() - lock_page() - f2fs_do_write_data_page() - set_page_writeback() [2st writeback] This problem was introduced by the previous commit 7377e853967b ("f2fs: compress: fix potential deadlock of compress file"). All pagelocks were released in f2fs_write_raw_pages(), but whether the page was in the writeback state was ignored in the subsequent writing process. Let's fix it by waiting for the page to writeback before writing.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 4c8ff7095bef64fc47e996a938f7d57f9e077da3, < a8226a45b2a9ce83ba7a167a387a00fecc319e71; >= 4c8ff7095bef64fc47e996a938f7d57f9e077da3, < 169134da419cb8ffbe3b0743bc24573e16952ea9; >= 4c8ff7095bef64fc47e996a938f7d57f9e077da3, < 6604df2a9d07ba8f8fb1ac14046c2c83776faa4f; >= 4c8ff7095bef64fc47e996a938f7d57f9e077da3, < 9940877c4fe752923a53f0f7372f2f152b6eccf0; >= 4c8ff7095bef64fc47e996a938f7d57f9e077da3, < ad31eed06c3b4d63b2d38322a271d4009aee4bb3; >= 4c8ff7095bef64fc47e996a938f7d57f9e077da3, < babedcbac164cec970872b8097401ca913a80e61 |
| Linux | Linux | 5.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-54068?
How severe is CVE-2023-54068?
How do I fix CVE-2023-54068?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-54062In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54063In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54064In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54065In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54066In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54067In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54069In the Linux kernel, the following vulnerability has been re…
- CVE-2023-5407Controller denial of service due to improper handling of a s…5.9
- CVE-2023-54070In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54071In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2023-54072In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54073In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2023-54068?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
