CVE-2022-49694
HIGH EPSS 13.5%
Published Feb 26, 20251y ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
Published Feb 26, 2025 1y ago
Last Modified Jun 17, 2026 1w ago
Description
In the Linux kernel, the following vulnerability has been resolved: block: disable the elevator int del_gendisk The elevator is only used for file system requests, which are stopped in del_gendisk. Move disabling the elevator and freeing the scheduler tags to the end of del_gendisk instead of doing that work in disk_release and blk_cleanup_queue to avoid a use after free on q->tag_set from disk_release as the tag_set might not be alive at that point. Move the blk_qos_exit call as well, as it just depends on the elevator exit and would be the only reason to keep the not exactly cheap queue freeze in disk_release.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
13.5% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-416 Use After Free Memory Safety
Affected Products 4
References 2
- git.kernel.org https://git.kernel.org/stable/c/50e34d78815e474d410f342fbe783b18192ca518
- git.kernel.org https://git.kernel.org/stable/c/f28699fafc047ec33299da01e928c3a0073c5cc6
Remediation
- git.kernel.org https://git.kernel.org/stable/c/50e34d78815e474d410f342fbe783b18192ca518
- git.kernel.org https://git.kernel.org/stable/c/f28699fafc047ec33299da01e928c3a0073c5cc6