{"id":"DEBIAN-CVE-2024-40943","details":"In the Linux kernel, the following vulnerability has been resolved:  ocfs2: fix races between hole punching and AIO+DIO  After commit \"ocfs2: return real error code in ocfs2_dio_wr_get_block\", fstests/generic/300 become from always failed to sometimes failed:  ======================================================================== [  473.293420 ] run fstests generic/300  [  475.296983 ] JBD2: Ignoring recovery information on journal [  475.302473 ] ocfs2: Mounting device (253,1) on (node local, slot 0) with ordered data mode. [  494.290998 ] OCFS2: ERROR (device dm-1): ocfs2_change_extent_flag: Owner 5668 has an extent at cpos 78723 which can no longer be found [  494.291609 ] On-disk corruption discovered. Please run fsck.ocfs2 once the filesystem is unmounted. [  494.292018 ] OCFS2: File system is now read-only. [  494.292224 ] (kworker/19:11,2628,19):ocfs2_mark_extent_written:5272 ERROR: status = -30 [  494.292602 ] (kworker/19:11,2628,19):ocfs2_dio_end_io_write:2374 ERROR: status = -3 fio: io_u error on file /mnt/scratch/racer: Read-only file system: write offset=460849152, buflen=131072 =========================================================================  In __blockdev_direct_IO, ocfs2_dio_wr_get_block is called to add unwritten extents to a list.  extents are also inserted into extent tree in ocfs2_write_begin_nolock.  Then another thread call fallocate to puch a hole at one of the unwritten extent.  The extent at cpos was removed by ocfs2_remove_extent().  At end io worker thread, ocfs2_search_extent_list found there is no such extent at the cpos.      T1                        T2                T3                               inode lock                                 ...                                 insert extents                                 ...                               inode unlock ocfs2_fallocate  __ocfs2_change_file_space   inode lock   lock ip_alloc_sem   ocfs2_remove_inode_range inode    ocfs2_remove_btree_range     ocfs2_remove_extent     ^---remove the extent at cpos 78723   ...   unlock ip_alloc_sem   inode unlock                                        ocfs2_dio_end_io                                         ocfs2_dio_end_io_write                                          lock ip_alloc_sem                                          ocfs2_mark_extent_written                                           ocfs2_change_extent_flag                                            ocfs2_search_extent_list                                            ^---failed to find extent                                           ...                                           unlock ip_alloc_sem  In most filesystems, fallocate is not compatible with racing with AIO+DIO, so fix it by adding to wait for all dio before fallocate/punch_hole like ext4.","modified":"2026-09-15T09:03:09.471647270Z","published":"2024-07-12T13:15:16.670Z","upstream":["CVE-2024-40943"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-40943"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.99-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-40943.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.9.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-40943.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.9.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-40943.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}