CVE-2022-49413
HIGH EPSS 19.1%
Published Feb 26, 20251y ago · Modified Jun 17, 20262w ago
7.8 CVSS 3.1
Published Feb 26, 2025 1y ago
Last Modified Jun 17, 2026 2w ago
Description
In the Linux kernel, the following vulnerability has been resolved: bfq: Update cgroup information before merging bio When the process is migrated to a different cgroup (or in case of writeback just starts submitting bios associated with a different cgroup) bfq_merge_bio() can operate with stale cgroup information in bic. Thus the bio can be merged to a request from a different cgroup or it can result in merging of bfqqs for different cgroups or bfqqs of already dead cgroups and causing possible use-after-free issues. Fix the problem by updating cgroup information in bfq_merge_bio().
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
19.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-416 Use After Free Memory Safety
Affected Products 5
References 6
- git.kernel.org https://git.kernel.org/stable/c/2a1077f17169a6059992a0bbdb330e0abad1e6d9
- git.kernel.org https://git.kernel.org/stable/c/b06691af08b41dfd81052a3362514d9827b44bb1
- git.kernel.org https://git.kernel.org/stable/c/d9165200c5627a2cf4408eefabdf0058bdf95e1a
- git.kernel.org https://git.kernel.org/stable/c/da9f3025d595956410ceaab2bea01980d7775948
- git.kernel.org https://git.kernel.org/stable/c/e8821f45612f2e6d9adb9c6ba0fb4184f57692aa
- git.kernel.org https://git.kernel.org/stable/c/ea591cd4eb270393810e7be01feb8fde6a34fbbe
Remediation
- git.kernel.org https://git.kernel.org/stable/c/2a1077f17169a6059992a0bbdb330e0abad1e6d9
- git.kernel.org https://git.kernel.org/stable/c/b06691af08b41dfd81052a3362514d9827b44bb1
- git.kernel.org https://git.kernel.org/stable/c/d9165200c5627a2cf4408eefabdf0058bdf95e1a
- git.kernel.org https://git.kernel.org/stable/c/da9f3025d595956410ceaab2bea01980d7775948
- git.kernel.org https://git.kernel.org/stable/c/e8821f45612f2e6d9adb9c6ba0fb4184f57692aa
- git.kernel.org https://git.kernel.org/stable/c/ea591cd4eb270393810e7be01feb8fde6a34fbbe