CVE-2022-49033

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/10/2024
Last modified:
30/10/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> btrfs: qgroup: fix sleep from invalid context bug in btrfs_qgroup_inherit()<br /> <br /> Syzkaller reported BUG as follows:<br /> <br /> BUG: sleeping function called from invalid context at<br /> include/linux/sched/mm.h:274<br /> Call Trace:<br /> <br /> dump_stack_lvl+0xcd/0x134<br /> __might_resched.cold+0x222/0x26b<br /> kmem_cache_alloc+0x2e7/0x3c0<br /> update_qgroup_limit_item+0xe1/0x390<br /> btrfs_qgroup_inherit+0x147b/0x1ee0<br /> create_subvol+0x4eb/0x1710<br /> btrfs_mksubvol+0xfe5/0x13f0<br /> __btrfs_ioctl_snap_create+0x2b0/0x430<br /> btrfs_ioctl_snap_create_v2+0x25a/0x520<br /> btrfs_ioctl+0x2a1c/0x5ce0<br /> __x64_sys_ioctl+0x193/0x200<br /> do_syscall_64+0x35/0x80<br /> <br /> Fix this by calling qgroup_dirty() on @dstqgroup, and update limit item in<br /> btrfs_run_qgroups() later outside of the spinlock context.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.14.301 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.15 (including) 4.19.268 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.20 (including) 5.4.226 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5 (including) 5.10.158 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.82 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.0.12 (excluding)
cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.1:rc6:*:*:*:*:*:*