В ядре Linux устранена следующая уязвимость:
ceph: привязанный массив num_export_targets для информации mds v2/v3
ceph_mdsmap_decode() в fs/ceph/mdsmap.c считывает num_export_targets из
каждую информационную запись per-mds и перемещает курсор декодирования на
num_export_targets * sizeof(u32) без предварительной проверки такого количества байтов
остаться. Единственная проверка верхней границы, которая ловит ускользающий курсор.
(*p > info_end) ограничивается info_v >= 4, поскольку info_end остается NULL
для info_v 2 и 3. Когда монитор отправляет карту MDS, чьи per-mds
info версия – 2 или 3 с увеличенным числом num_export_targets, курсор
проходит мимо переднего буфера сообщения и последующего цикла целей экспорта
вызывает непроверенную функцию ceph_decode_32() для памяти, находящейся за пределами границ.
Клиент ядра обрабатывает CEPH_MSG_MDS_MAP из своего сеанса мониторинга.
(net/ceph/mon_client.c отправляет его; fs/ceph/super.c направляет его
ceph_mdsc_handle_mdsmap(), который устанавливает конец границы переднего буфера и
вызывает ceph_mdsmap_decode()). Вредоносный или скомпрометированный монитор или
злоумышленник на пути к неподписанному/незашифрованному сеансу обмена сообщениями может
поэтому управляйте чтением за пределами допустимого диапазона в ядре клиента; на x86_64
с KASAN сообщается, что чтение за пределами поля
ceph_mdsmap_decode(). Декодированные значения попадают во внутренний
info->export_targets[] массив, поэтому следствием является ядро
чтение за пределами границ, а не утечка информации злоумышленнику.
Воздействие: вредоносный или скомпрометированный монитор Ceph отправляет карту MDS с
версия информации для каждого mds 2 или 3 и увеличенный размер num_export_targets
Поле запускает чтение за пределами допустимого диапазона в ядре клиента CephFS. Прежде чем двигаться дальше, добавьте ceph_decode_need() для массива целей экспорта.
курсор, поэтому граница применяется для каждого info_v >= 2, не только
info_v >= 4. Это отражает идиому «посчитать, затем нужно», уже используемую для
m_data_pg_pools позже в той же функции.
Вычислите количество байтов целей экспорта с помощью size_mul() и повторно используйте это значение.
проверяемая длина при перемещении курсора, поэтому контролируемая злоумышленником
Умножение num_export_targets не закрывается при переполнении, а не
полагаясь на более позднюю защиту kcalloc().
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: ceph: bound num_export_targets array for mds info v2/v3 ceph_mdsmap_decode() in fs/ceph/mdsmap.c reads num_export_targets from each per-mds info record and advances the decode cursor by num_export_targets * sizeof(u32) without first checking that many bytes remain. The only upper-bound check that catches a runaway cursor (*p > info_end) is gated on info_v >= 4, because info_end is left NULL for info_v 2 and 3. When the monitor sends an MDS map whose per-mds info version is 2 or 3 with an oversized num_export_targets, the cursor moves past the message front buffer and the later export-targets loop calls the unchecked ceph_decode_32() on out-of-bounds memory. A kernel client processes CEPH_MSG_MDS_MAP from its monitor session (net/ceph/mon_client.c dispatches it; fs/ceph/super.c routes it to ceph_mdsc_handle_mdsmap(), which sets end to the front buffer bound and calls ceph_mdsmap_decode()). A malicious or compromised monitor, or an on-path attacker on an unsigned/unencrypted messenger session, can therefore drive an out-of-bounds read in the client kernel; on x86_64 with KASAN it is reported as a slab-out-of-bounds read in ceph_mdsmap_decode(). The decoded values land in the internal info->export_targets[] array, so the consequence is a kernel out-of-bounds read, not an information leak to the attacker. Impact: a malicious or compromised Ceph monitor sending an MDS map with a per-mds info version of 2 or 3 and an oversized num_export_targets field triggers an out-of-bounds read in the CephFS client kernel. Add a ceph_decode_need() for the export-targets array before advancing the cursor, so the bound is enforced for every info_v >= 2, not only info_v >= 4. This mirrors the count-then-need idiom already used for m_data_pg_pools later in the same function. Compute the export-targets byte count with size_mul() and reuse that checked length when advancing the cursor, so the attacker-controlled num_export_targets multiplication fails closed on overflow rather than relying on the later kcalloc() guard.
Характеристики атаки
Последствия
Строка CVSS v3.1