CVE-2023-53513
Description
In the Linux kernel, the following vulnerability has been resolved:
nbd: fix incomplete validation of ioctl arg
We tested and found an alarm caused by nbd_ioctl arg without verification. The UBSAN warning calltrace like below:
UBSAN: Undefined behaviour in fs/buffer.c:1709:35 signed integer overflow: -9223372036854775808 - 1 cannot be represented in type 'long long int' CPU: 3 PID: 2523 Comm: syz-executor.0 Not tainted 4.19.90 #1 Hardware name: linux,dummy-virt (DT) Call trace: dump_backtrace+0x0/0x3f0 arch/arm64/kernel/time.c:78 show_stack+0x28/0x38 arch/arm64/kernel/traps.c:158 __dump_stack lib/dump_stack.c:77 [inline] dump_stack+0x170/0x1dc lib/dump_stack.c:118 ubsan_epilogue+0x18/0xb4 lib/ubsan.c:161 handle_overflow+0x188/0x1dc lib/ubsan.c:192 __ubsan_handle_sub_overflow+0x34/0x44 lib/ubsan.c:206 __block_write_full_page+0x94c/0xa20 fs/buffer.c:1709 block_write_full_page+0x1f0/0x280 fs/buffer.c:2934 blkdev_writepage+0x34/0x40 fs/block_dev.c:607 __writepage+0x68/0xe8 mm/page-writeback.c:2305 write_cache_pages+0x44c/0xc70 mm/page-writeback.c:2240 generic_writepages+0xdc/0x148 mm/page-writeback.c:2329 blkdev_writepages+0x2c/0x38 fs/block_dev.c:2114 do_writepages+0xd4/0x250 mm/page-writeback.c:2344
The reason for triggering this warning is __block_write_full_page() -> i_size_read(inode) - 1 overflow. inode->i_size is assigned in __nbd_ioctl() -> nbd_set_size() -> bytesize. We think it is necessary to limit the size of arg to prevent errors.
Moreover, __nbd_ioctl() -> nbd_add_socket(), arg will be cast to int. Assuming the value of arg is 0x80000000000000001) (on a 64-bit machine), it will become 1 after the coercion, which will return unexpected results.
Fix it by adding checks to prevent passing in too large numbers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
85- osv-coords83 versionspkg:rpm/almalinux/bpftoolpkg:rpm/almalinux/kernelpkg:rpm/almalinux/kernel-abi-stablelistspkg:rpm/almalinux/kernel-corepkg:rpm/almalinux/kernel-cross-headerspkg:rpm/almalinux/kernel-debugpkg:rpm/almalinux/kernel-debug-corepkg:rpm/almalinux/kernel-debug-develpkg:rpm/almalinux/kernel-debug-modulespkg:rpm/almalinux/kernel-debug-modules-extrapkg:rpm/almalinux/kernel-develpkg:rpm/almalinux/kernel-docpkg:rpm/almalinux/kernel-headerspkg:rpm/almalinux/kernel-modulespkg:rpm/almalinux/kernel-modules-extrapkg:rpm/almalinux/kernel-rtpkg:rpm/almalinux/kernel-rt-corepkg:rpm/almalinux/kernel-rt-debugpkg:rpm/almalinux/kernel-rt-debug-corepkg:rpm/almalinux/kernel-rt-debug-develpkg:rpm/almalinux/kernel-rt-debug-modulespkg:rpm/almalinux/kernel-rt-debug-modules-extrapkg:rpm/almalinux/kernel-rt-develpkg:rpm/almalinux/kernel-rt-modulespkg:rpm/almalinux/kernel-rt-modules-extrapkg:rpm/almalinux/kernel-toolspkg:rpm/almalinux/kernel-tools-libspkg:rpm/almalinux/kernel-tools-libs-develpkg:rpm/almalinux/kernel-zfcpdumppkg:rpm/almalinux/kernel-zfcpdump-corepkg:rpm/almalinux/kernel-zfcpdump-develpkg:rpm/almalinux/kernel-zfcpdump-modulespkg:rpm/almalinux/kernel-zfcpdump-modules-extrapkg:rpm/almalinux/perfpkg:rpm/almalinux/python3-perfpkg:rpm/suse/kernel-64kb&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/kernel-64kb&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/kernel-64kb&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/kernel-default-base&distro=SUSE%20Manager%20Proxy%20LTS%204.3pkg:rpm/suse/kernel-default-base&distro=SUSE%20Manager%20Server%20LTS%204.3pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP4pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP4pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/kernel-default&distro=SUSE%20Manager%20Proxy%20LTS%204.3pkg:rpm/suse/kernel-default&distro=SUSE%20Manager%20Server%20LTS%204.3pkg:rpm/suse/kernel-docs&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/kernel-docs&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/kernel-docs&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/kernel-docs&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/kernel-livepatch-SLE15-SP4_Update_45&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP4pkg:rpm/suse/kernel-obs-build&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/kernel-obs-build&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/kernel-obs-build&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/kernel-obs-build&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/kernel-source&distro=SUSE%20Manager%20Proxy%20LTS%204.3pkg:rpm/suse/kernel-source&distro=SUSE%20Manager%20Server%20LTS%204.3pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/kernel-syms&distro=SUSE%20Manager%20Proxy%20LTS%204.3pkg:rpm/suse/kernel-syms&distro=SUSE%20Manager%20Server%20LTS%204.3pkg:rpm/suse/kernel-zfcpdump&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/kernel-zfcpdump&distro=SUSE%20Manager%20Server%20LTS%204.3
< 4.18.0-553.87.1.el8_10+ 82 more
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.rt7.428.el8_10
- (no CPE)range: < 4.18.0-553.87.1.rt7.428.el8_10
- (no CPE)range: < 4.18.0-553.87.1.rt7.428.el8_10
- (no CPE)range: < 4.18.0-553.87.1.rt7.428.el8_10
- (no CPE)range: < 4.18.0-553.87.1.rt7.428.el8_10
- (no CPE)range: < 4.18.0-553.87.1.rt7.428.el8_10
- (no CPE)range: < 4.18.0-553.87.1.rt7.428.el8_10
- (no CPE)range: < 4.18.0-553.87.1.rt7.428.el8_10
- (no CPE)range: < 4.18.0-553.87.1.rt7.428.el8_10
- (no CPE)range: < 4.18.0-553.87.1.rt7.428.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 4.18.0-553.87.1.el8_10
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1.150400.24.92.1
- (no CPE)range: < 5.14.21-150400.24.179.1.150400.24.92.1
- (no CPE)range: < 5.14.21-150400.24.179.1.150400.24.92.1
- (no CPE)range: < 5.14.21-150400.24.179.1.150400.24.92.1
- (no CPE)range: < 5.14.21-150400.24.179.1.150400.24.92.1
- (no CPE)range: < 5.14.21-150400.24.179.1.150400.24.92.1
- (no CPE)range: < 5.14.21-150400.24.179.1.150400.24.92.1
- (no CPE)range: < 5.14.21-150400.24.179.1.150400.24.92.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 1-150400.9.3.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.15.133.1
- (no CPE)range: < 5.14.21-150400.15.133.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.15.133.1
- (no CPE)range: < 5.14.21-150400.15.133.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
- (no CPE)range: < 5.14.21-150400.24.179.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.