CVE-2022-49411
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
26/02/2025
Last modified:
25/03/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
bfq: Make sure bfqg for which we are queueing requests is online<br />
<br />
Bios queued into BFQ IO scheduler can be associated with a cgroup that<br />
was already offlined. This may then cause insertion of this bfq_group<br />
into a service tree. But this bfq_group will get freed as soon as last<br />
bio associated with it is completed leading to use after free issues for<br />
service tree users. Fix the problem by making sure we always operate on<br />
online bfq_group. If the bfq_group associated with the bio is not<br />
online, we pick the first online parent.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.12 (including) | 5.4.198 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5 (including) | 5.10.121 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.46 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 5.17.14 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.18 (including) | 5.18.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/075a53b78b815301f8d3dd1ee2cd99554e34f0dd
- https://git.kernel.org/stable/c/51f724bffa3403a5236597e6b75df7329c1ec6e9
- https://git.kernel.org/stable/c/6ee0868b0c3ccead5907685fcdcdd0c08dfe4b0b
- https://git.kernel.org/stable/c/7781c38552e6cc54ed8e9040279561340516b881
- https://git.kernel.org/stable/c/97bd6c56bdcb41079e488e31df56809e3b2ce628
- https://git.kernel.org/stable/c/ccddf8cd411c1800863ed357064e56ceffd356bb