CVE-2024-50250 (GCVE-0-2024-50250)
Vulnerability from cvelistv5
Published
2024-11-09 10:14
Modified
2026-08-05 11:42
Summary
In the Linux kernel, the following vulnerability has been resolved: fsdax: dax_unshare_iter needs to copy entire blocks The code that copies data from srcmap to iomap in dax_unshare_iter is very very broken, which bfoster's recent fsx changes have exposed. If the pos and len passed to dax_file_unshare are not aligned to an fsblock boundary, the iter pos and length in the _iter function will reflect this unalignment. dax_iomap_direct_access always returns a pointer to the start of the kmapped fsdax page, even if its pos argument is in the middle of that page. This is catastrophic for data integrity when iter->pos is not aligned to a page, because daddr/saddr do not point to the same byte in the file as iter->pos. Hence we corrupt user data by copying it to the wrong place. If iter->pos + iomap_length() in the _iter function not aligned to a page, then we fail to copy a full block, and only partially populate the destination block. This is catastrophic for data confidentiality because we expose stale pmem contents. Fix both of these issues by aligning copy_pos/copy_len to a page boundary (remember, this is fsdax so 1 fsblock == 1 base page) so that we always copy full blocks. We're not done yet -- there's no call to invalidate_inode_pages2_range, so programs that have the file range mmap'd will continue accessing the old memory mapping after the file metadata updates have completed. Be careful with the return value -- if the unshare succeeds, we still need to return the number of bytes that the iomap iter thinks we're operating on.
Impacted products
Vendor Product Version
Linux Linux Version: 1bec6782a25c9b92c203ea7a1b3e3dc6a468cbc4
Version: d984648e428bf88cbd94ebe346c73632cb92fffb
Version: d984648e428bf88cbd94ebe346c73632cb92fffb
Version: d984648e428bf88cbd94ebe346c73632cb92fffb
Version: 6.1.113   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "NONE",
              "baseScore": 7.1,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2024-50250",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-01T20:15:51.723590Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "description": "CWE-noinfo Not enough information",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-01T20:17:25.089Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:27:30.252Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/dax.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "bdbc96c23197d773a7d1bf03e4f11de593b0ff28",
              "status": "affected",
              "version": "1bec6782a25c9b92c203ea7a1b3e3dc6a468cbc4",
              "versionType": "git"
            },
            {
              "lessThan": "9bc18bb476e50e32e5d08f2734d63d63e0fa528c",
              "status": "affected",
              "version": "d984648e428bf88cbd94ebe346c73632cb92fffb",
              "versionType": "git"
            },
            {
              "lessThan": "8e9c0f500b42216ef930f5c0d1703989a451913d",
              "status": "affected",
              "version": "d984648e428bf88cbd94ebe346c73632cb92fffb",
              "versionType": "git"
            },
            {
              "lessThan": "50793801fc7f6d08def48754fb0f0706b0cfc394",
              "status": "affected",
              "version": "d984648e428bf88cbd94ebe346c73632cb92fffb",
              "versionType": "git"
            },
            {
              "lessThan": "6.1.116",
              "status": "affected",
              "version": "6.1.113",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/dax.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.2"
            },
            {
              "lessThan": "6.2",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.116",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.60",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.7",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.12",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.116",
                  "versionStartIncluding": "6.1.113",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.60",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.7",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfsdax: dax_unshare_iter needs to copy entire blocks\n\nThe code that copies data from srcmap to iomap in dax_unshare_iter is\nvery very broken, which bfoster\u0027s recent fsx changes have exposed.\n\nIf the pos and len passed to dax_file_unshare are not aligned to an\nfsblock boundary, the iter pos and length in the _iter function will\nreflect this unalignment.\n\ndax_iomap_direct_access always returns a pointer to the start of the\nkmapped fsdax page, even if its pos argument is in the middle of that\npage.  This is catastrophic for data integrity when iter-\u003epos is not\naligned to a page, because daddr/saddr do not point to the same byte in\nthe file as iter-\u003epos.  Hence we corrupt user data by copying it to the\nwrong place.\n\nIf iter-\u003epos + iomap_length() in the _iter function not aligned to a\npage, then we fail to copy a full block, and only partially populate the\ndestination block.  This is catastrophic for data confidentiality\nbecause we expose stale pmem contents.\n\nFix both of these issues by aligning copy_pos/copy_len to a page\nboundary (remember, this is fsdax so 1 fsblock == 1 base page) so that\nwe always copy full blocks.\n\nWe\u0027re not done yet -- there\u0027s no call to invalidate_inode_pages2_range,\nso programs that have the file range mmap\u0027d will continue accessing the\nold memory mapping after the file metadata updates have completed.\n\nBe careful with the return value -- if the unshare succeeds, we still\nneed to return the number of bytes that the iomap iter thinks we\u0027re\noperating on."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The only path to `dax_unshare_iter` is the local `fallocate(FALLOC_FL_UNSHARE_RANGE)` syscall on an XFS+DAX file; no network service (nfsd, ksmbd) ever issues that fallocate mode, so no remote reach exists.\nAC:L - The attacker fully controls the offset/length passed to fallocate, so simply supplying a non-page-aligned range deterministically triggers both the misplaced copy and the uncopied stale tail \u2014 no race, no memory-layout dependency, no condition outside attacker control.\nPR:L - `vfs_fallocate` only requires an fd opened with `FMODE_WRITE`; any unprivileged local user can create a file, clone it with `FICLONE` to create shared blocks, and unshare it \u2014 no capability or root is needed.\nUI:N - The attacker performs every step (create, reflink, fallocate, read back) with no victim action required; the mmap-staleness variant can also be set up entirely by the attacker\u0027s own process.\nS:U - The corruption and disclosure occur within filesystem data managed by the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The unshare leaves the tail of every freshly allocated destination block uncopied, exposing raw stale pmem contents of previously freed blocks \u2014 the commit calls this \"catastrophic for data confidentiality\" \u2014 and it is repeatable to harvest large amounts of other users\u0027 deleted file data.\nI:H - Data is copied to the wrong offsets, silently destroying user file contents (\"catastrophic for data integrity\"), and the missing `invalidate_inode_pages2_range` leaves writable mappings aimed at still-shared blocks, allowing writes to modify other files\u0027 data.\nA:H - Irrecoverable on-disk data destruction plus writes through stale DAX mappings into blocks that may be reallocated as XFS metadata lead to filesystem corruption and forced shutdown, rendering the filesystem unusable."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:42:46.493Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bdbc96c23197d773a7d1bf03e4f11de593b0ff28"
        },
        {
          "url": "https://git.kernel.org/stable/c/9bc18bb476e50e32e5d08f2734d63d63e0fa528c"
        },
        {
          "url": "https://git.kernel.org/stable/c/8e9c0f500b42216ef930f5c0d1703989a451913d"
        },
        {
          "url": "https://git.kernel.org/stable/c/50793801fc7f6d08def48754fb0f0706b0cfc394"
        }
      ],
      "title": "fsdax: dax_unshare_iter needs to copy entire blocks",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-50250",
    "datePublished": "2024-11-09T10:14:59.003Z",
    "dateReserved": "2024-10-21T19:36:19.979Z",
    "dateUpdated": "2026-08-05T11:42:46.493Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T22:27:30.252Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 7.1, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"NONE\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"HIGH\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-50250\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-10-01T20:15:51.723590Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"description\": \"CWE-noinfo Not enough information\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-10-01T15:24:53.985Z\"}}], \"cna\": {\"title\": \"fsdax: dax_unshare_iter needs to copy entire blocks\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The only path to `dax_unshare_iter` is the local `fallocate(FALLOC_FL_UNSHARE_RANGE)` syscall on an XFS+DAX file; no network service (nfsd, ksmbd) ever issues that fallocate mode, so no remote reach exists.\\nAC:L - The attacker fully controls the offset/length passed to fallocate, so simply supplying a non-page-aligned range deterministically triggers both the misplaced copy and the uncopied stale tail \\u2014 no race, no memory-layout dependency, no condition outside attacker control.\\nPR:L - `vfs_fallocate` only requires an fd opened with `FMODE_WRITE`; any unprivileged local user can create a file, clone it with `FICLONE` to create shared blocks, and unshare it \\u2014 no capability or root is needed.\\nUI:N - The attacker performs every step (create, reflink, fallocate, read back) with no victim action required; the mmap-staleness variant can also be set up entirely by the attacker\u0027s own process.\\nS:U - The corruption and disclosure occur within filesystem data managed by the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\\nC:H - The unshare leaves the tail of every freshly allocated destination block uncopied, exposing raw stale pmem contents of previously freed blocks \\u2014 the commit calls this \\\"catastrophic for data confidentiality\\\" \\u2014 and it is repeatable to harvest large amounts of other users\u0027 deleted file data.\\nI:H - Data is copied to the wrong offsets, silently destroying user file contents (\\\"catastrophic for data integrity\\\"), and the missing `invalidate_inode_pages2_range` leaves writable mappings aimed at still-shared blocks, allowing writes to modify other files\u0027 data.\\nA:H - Irrecoverable on-disk data destruction plus writes through stale DAX mappings into blocks that may be reallocated as XFS metadata lead to filesystem corruption and forced shutdown, rendering the filesystem unusable.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"1bec6782a25c9b92c203ea7a1b3e3dc6a468cbc4\", \"lessThan\": \"bdbc96c23197d773a7d1bf03e4f11de593b0ff28\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d984648e428bf88cbd94ebe346c73632cb92fffb\", \"lessThan\": \"9bc18bb476e50e32e5d08f2734d63d63e0fa528c\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d984648e428bf88cbd94ebe346c73632cb92fffb\", \"lessThan\": \"8e9c0f500b42216ef930f5c0d1703989a451913d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d984648e428bf88cbd94ebe346c73632cb92fffb\", \"lessThan\": \"50793801fc7f6d08def48754fb0f0706b0cfc394\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6.1.113\", \"lessThan\": \"6.1.116\", \"versionType\": \"semver\"}], \"programFiles\": [\"fs/dax.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6.2\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"6.2\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.1.116\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.60\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11.7\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.11.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"fs/dax.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/bdbc96c23197d773a7d1bf03e4f11de593b0ff28\"}, {\"url\": \"https://git.kernel.org/stable/c/9bc18bb476e50e32e5d08f2734d63d63e0fa528c\"}, {\"url\": \"https://git.kernel.org/stable/c/8e9c0f500b42216ef930f5c0d1703989a451913d\"}, {\"url\": \"https://git.kernel.org/stable/c/50793801fc7f6d08def48754fb0f0706b0cfc394\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nfsdax: dax_unshare_iter needs to copy entire blocks\\n\\nThe code that copies data from srcmap to iomap in dax_unshare_iter is\\nvery very broken, which bfoster\u0027s recent fsx changes have exposed.\\n\\nIf the pos and len passed to dax_file_unshare are not aligned to an\\nfsblock boundary, the iter pos and length in the _iter function will\\nreflect this unalignment.\\n\\ndax_iomap_direct_access always returns a pointer to the start of the\\nkmapped fsdax page, even if its pos argument is in the middle of that\\npage.  This is catastrophic for data integrity when iter-\u003epos is not\\naligned to a page, because daddr/saddr do not point to the same byte in\\nthe file as iter-\u003epos.  Hence we corrupt user data by copying it to the\\nwrong place.\\n\\nIf iter-\u003epos + iomap_length() in the _iter function not aligned to a\\npage, then we fail to copy a full block, and only partially populate the\\ndestination block.  This is catastrophic for data confidentiality\\nbecause we expose stale pmem contents.\\n\\nFix both of these issues by aligning copy_pos/copy_len to a page\\nboundary (remember, this is fsdax so 1 fsblock == 1 base page) so that\\nwe always copy full blocks.\\n\\nWe\u0027re not done yet -- there\u0027s no call to invalidate_inode_pages2_range,\\nso programs that have the file range mmap\u0027d will continue accessing the\\nold memory mapping after the file metadata updates have completed.\\n\\nBe careful with the return value -- if the unshare succeeds, we still\\nneed to return the number of bytes that the iomap iter thinks we\u0027re\\noperating on.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.116\", \"versionStartIncluding\": \"6.1.113\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.60\", \"versionStartIncluding\": \"6.2\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11.7\", \"versionStartIncluding\": \"6.2\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12\", \"versionStartIncluding\": \"6.2\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:42:46.493Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-50250\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:42:46.493Z\", \"dateReserved\": \"2024-10-21T19:36:19.979Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-11-09T10:14:59.003Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…