Overview
Some operations after mounting a crafted image can cause an unknown bug that shows register information to a normal user via the dmesg command.
Target
Linux Kernel 5.3.11 BTRFS filesystem. The issue affects __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12.
Bug type: Information Disclosure.
Note: the BTRFS development team disputes this issue as not being a vulnerability, arguing that (1) the kernel provides dmesg_restrict=1 to restrict dmesg access, leaving it to the administrator, and (2) WARN/WARN_ON are widely used across the kernel, so treating this as a CVE would imply thousands of similar CVEs.
Reproduce
gcc -o poc poc_2019_19039.c
mkdir mnt
mount poc_2019_19039.img ./mnt
cp poc ./mnt/
cd mnt
./pocRoot cause
fs/btrfs/extent-tree.c:4582 (link)
}
extent_slot = path->slots[0];
}
[1] } else if (WARN_ON(ret == -ENOENT)) {
[2] btrfs_print_leaf(path->nodes[0]); //
btrfs_err(info,
"unable to find ref byte nr %llu parent %llu root %llu owner %llu offset %llu",
bytenr, parent, root_objectid, owner_objectid,
owner_offset);
btrfs_abort_transaction(trans, ret);
goto out;
} else {
btrfs_abort_transaction(trans, ret);
goto out;
}In [1], the local variable ret is -ENOENT. The kernel calls btrfs_print_leaf, which shows register information to normal-privilege users.
Debugger / KASAN
KASAN / WARNING log (trimmed to the relevant frames). The garbled bytes at the top are leaked memory content; the btrfs_print_leaf dump follows the WARNING:
[ 163.913497] ------------[ cut here ]------------
[ 163.913717] WARNING: CPU: 0 PID: 230 at fs/btrfs/extent-tree.c:4851 __btrfs_free_extent.isra.67+0x842/0xd60
[ 163.913717] CPU: 0 PID: 230 Comm: 212 Not tainted 5.3.11 #1
[ 163.913717] RIP: 0010:__btrfs_free_extent.isra.67+0x842/0xd60
[ 163.913717] Call Trace:
[ 163.913717] __btrfs_run_delayed_refs+0xd96/0x1ba0
[ 163.913717] btrfs_run_delayed_refs+0x120/0x200
[ 163.913717] btrfs_commit_transaction+0x7da/0x1100
[ 163.913717] btrfs_sync_file+0x71c/0x767
[ 163.913717] do_fsync+0x33/0x60
[ 163.913717] __x64_sys_fsync+0x18/0x20
[ 163.913717] do_syscall_64+0x5e/0x190
[ 163.913717] entry_SYSCALL_64_after_hwframe+0x44/0xa9
[ 163.913717] ---[ end trace 91cdd991a622b34f ]---
[ 163.947792] BTRFS info (device loop0): leaf 29401088 gen 9 total ptrs 15 free space 3132 owner 2
[ 163.951632] item 0 key (12582912 168 8192) itemoff 3942 itemsize 53
[ 163.955430] extent refs 1 gen 9 flags 1
...
[ 164.009739] BTRFS error (device loop0): unable to find ref byte nr 29417472 parent 0 root 1 owner 0 offset 0
[ 164.013356] ------------[ cut here ]------------
[ 164.015651] WARNING: CPU: 0 PID: 230 at fs/btrfs/extent-tree.c:4857 __btrfs_free_extent.isra.67+0x8b7/0xd60
...
[ 164.050349] BTRFS: error (device loop0) in __btrfs_free_extent:4857: errno=-2 No such entry
[ 164.053543] BTRFS info (device loop0): forced readonly
Mounting a crafted btrfs image leaks register information. A normal user calling dmesg sees register values (Kernel Base, Heap Base, GS, CR registers, etc.), which can aid other vulnerability exploitation.
Details
CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N), CWE-532, published 2019-11-21, last modified 2024-11-21.
Attribution
Found as part of the Best of the Best (BoB) 8th bobfuzzer team project — a five-person team that ported the JANUS file-system fuzzer. This is team work, not sole authorship.