CVE-2023-53622
Description
A race condition was found in the Linux kernel's GFS2 filesystem in the mount options display logic. A local user can trigger this issue by concurrently reading filesystem mount options while another process modifies filesystem tuning parameters, causing gfs2_show_options to read fields like gt_logd_secs without holding the gt_spin lock. This results in data races that can produce inconsistent or corrupted output, potentially leading to denial of service through system instability.
Statement
The gfs2_show_options function displays filesystem mount options by reading various tuning parameters from the gfs2_tune structure. While concurrent modifications of these parameters via gfs2_reconfigure acquire the gt_spin lock for protection, the read operations in gfs2_show_options do not hold this lock. This creates classic data races where reads and writes to the same memory locations occur simultaneously without synchronization. While the immediate effect is inconsistent mount option output, the unsynchronized memory access violates kernel memory ordering assumptions and could potentially trigger more serious issues depending on the underlying architecture and compiler optimizations.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 5.5 | 7 | N/A |
| Attack Vector | Local | Local | N/A |
| Attack Complexity | Low | High | N/A |
| Privileges Required | Low | Low | N/A |
| User Interaction | None | None | N/A |
| Scope | Unchanged | Unchanged | N/A |
| Confidentiality | None | High | N/A |
| Integrity Impact | None | High | N/A |
| Availability Impact | High | High | N/A |
Vector
Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Understanding the Weakness (CWE)
Integrity,Confidentiality,Other
Technical Impact: Modify Application Data; Read Application Data; Alter Execution Logic
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.