Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the Linux kernel's Ceph file system could allow a malicious metadata server to disclose adjacent kernel heap bytes to a local user. This occurs when a specific attribute's value length is incorrectly handled, leading to an out-of-bounds read. The issue has been resolved by adding a check to ensure the value length does not exceed the available data within the blob.
- Kernel code flaw exposes sensitive data.
- Matters for data security and integrity.
- Confirm relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker with control over a Ceph metadata server could craft a special attribute that, when read by a local user through the `getxattr` system call, exposes adjacent kernel memory. This occurs because the Linux kernel's Ceph component in `__build_xattrs()` doesn't properly check the bounds of the final attribute's value length, allowing it to exceed the allocated buffer.
- Requires a compromised metadata server.
- Triggered by a local user's `getxattr` call.
- Discloses sensitive kernel memory.
Live Threat
Current exploitation, exposure, and threat context
A malicious or compromised metadata server could disclose adjacent kernel heap bytes to a local user. This could happen when a local user performs a `getxattr(2)` operation on a CephFS file. The vulnerability involves an unchecked value length in the final attribute of an xattr blob, potentially allowing an attacker to read beyond the allocated buffer.
- Kernel heap data at risk.
- Malicious metadata server, local user trigger.
- Disclosure of adjacent kernel memory.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts the Linux kernel's handling of extended attributes within the Ceph filesystem. Responsibility for remediation likely falls to teams managing the Ceph infrastructure and the Linux kernel instances where CephFS is deployed, potentially including platform or storage administrators. The immediate first step is to confirm the presence of vulnerable CephFS deployments, assess their exposure and criticality, and then coordinate with relevant teams and potentially vendors to plan a fix.
- Identify CephFS deployments and owners.
- Verify user-accessible CephFS file systems.
- Plan vendor coordination and kernel updates.