Skip to content
cvekernelbtrfsinformation-disclosure

Linux kernel btrfs information disclosure

3 min read

Overview

Some operations after mounting a crafted image can cause an unknown bug that shows register information to a normal user via the dmesg command.

Target

Linux Kernel 5.3.11 BTRFS filesystem. The issue affects __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12.

Bug type: Information Disclosure.

Note: the BTRFS development team disputes this issue as not being a vulnerability, arguing that (1) the kernel provides dmesg_restrict=1 to restrict dmesg access, leaving it to the administrator, and (2) WARN/WARN_ON are widely used across the kernel, so treating this as a CVE would imply thousands of similar CVEs.

Reproduce

gcc -o poc poc_2019_19039.c
mkdir mnt
mount poc_2019_19039.img ./mnt
cp poc ./mnt/
cd mnt
./poc

Root cause

fs/btrfs/extent-tree.c:4582 (link)

      }
      extent_slot = path->slots[0];
    }
[1]  } else if (WARN_ON(ret == -ENOENT)) {
[2]    btrfs_print_leaf(path->nodes[0]); //
    btrfs_err(info,
      "unable to find ref byte nr %llu parent %llu root %llu  owner %llu offset %llu",
      bytenr, parent, root_objectid, owner_objectid,
      owner_offset);
      btrfs_abort_transaction(trans, ret);
      goto out;
  } else {
    btrfs_abort_transaction(trans, ret);
    goto out;
  }

In [1], the local variable ret is -ENOENT. The kernel calls btrfs_print_leaf, which shows register information to normal-privilege users.

Debugger / KASAN

KASAN / WARNING log (trimmed to the relevant frames). The garbled bytes at the top are leaked memory content; the btrfs_print_leaf dump follows the WARNING:

[  163.913497] ------------[ cut here ]------------
[  163.913717] WARNING: CPU: 0 PID: 230 at fs/btrfs/extent-tree.c:4851 __btrfs_free_extent.isra.67+0x842/0xd60
[  163.913717] CPU: 0 PID: 230 Comm: 212 Not tainted 5.3.11 #1
[  163.913717] RIP: 0010:__btrfs_free_extent.isra.67+0x842/0xd60
[  163.913717] Call Trace:
[  163.913717]  __btrfs_run_delayed_refs+0xd96/0x1ba0
[  163.913717]  btrfs_run_delayed_refs+0x120/0x200
[  163.913717]  btrfs_commit_transaction+0x7da/0x1100
[  163.913717]  btrfs_sync_file+0x71c/0x767
[  163.913717]  do_fsync+0x33/0x60
[  163.913717]  __x64_sys_fsync+0x18/0x20
[  163.913717]  do_syscall_64+0x5e/0x190
[  163.913717]  entry_SYSCALL_64_after_hwframe+0x44/0xa9
[  163.913717] ---[ end trace 91cdd991a622b34f ]---
[  163.947792] BTRFS info (device loop0): leaf 29401088 gen 9 total ptrs 15 free space 3132 owner 2
[  163.951632] 	item 0 key (12582912 168 8192) itemoff 3942 itemsize 53
[  163.955430] 		extent refs 1 gen 9 flags 1
...
[  164.009739] BTRFS error (device loop0): unable to find ref byte nr 29417472 parent 0 root 1  owner 0 offset 0
[  164.013356] ------------[ cut here ]------------
[  164.015651] WARNING: CPU: 0 PID: 230 at fs/btrfs/extent-tree.c:4857 __btrfs_free_extent.isra.67+0x8b7/0xd60
...
[  164.050349] BTRFS: error (device loop0) in __btrfs_free_extent:4857: errno=-2 No such entry
[  164.053543] BTRFS info (device loop0): forced readonly

Mounting a crafted btrfs image leaks register information. A normal user calling dmesg sees register values (Kernel Base, Heap Base, GS, CR registers, etc.), which can aid other vulnerability exploitation.

Details

CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N), CWE-532, published 2019-11-21, last modified 2024-11-21.

Attribution

Found as part of the Best of the Best (BoB) 8th bobfuzzer team project — a five-person team that ported the JANUS file-system fuzzer. This is team work, not sole authorship.

References