CVE-2022-49411
published 2025-02-26CVE-2022-49411: In the Linux kernel, the following vulnerability has been resolved: bfq: Make sure bfqg for which we are queueing requests is online Bios queued into BFQ IO…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
bfq: Make sure bfqg for which we are queueing requests is online
Bios queued into BFQ IO scheduler can be associated with a cgroup that
was already offlined. This may then cause insertion of this bfq_group
into a service tree. But this bfq_group will get freed as soon as last
bio associated with it is completed leading to use after free issues for
service tree users. Fix the problem by making sure we always operate on
online bfq_group. If the bfq_group associated with the bio is not
online, we pick the first online parent.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.5-1 (bookworm) | linux 5.18.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= e21b7a0b988772e82e7147e1c659a5afe2ae003c < ccddf8cd411c1800863ed357064e56ceffd356bb | ccddf8cd411c1800863ed357064e56ceffd356bb |
| linux | linux | >= e21b7a0b988772e82e7147e1c659a5afe2ae003c < 51f724bffa3403a5236597e6b75df7329c1ec6e9 | 51f724bffa3403a5236597e6b75df7329c1ec6e9 |
| linux | linux | >= e21b7a0b988772e82e7147e1c659a5afe2ae003c < 6ee0868b0c3ccead5907685fcdcdd0c08dfe4b0b | 6ee0868b0c3ccead5907685fcdcdd0c08dfe4b0b |
| linux | linux | >= e21b7a0b988772e82e7147e1c659a5afe2ae003c < 97bd6c56bdcb41079e488e31df56809e3b2ce628 | 97bd6c56bdcb41079e488e31df56809e3b2ce628 |
| linux | linux | >= e21b7a0b988772e82e7147e1c659a5afe2ae003c < 7781c38552e6cc54ed8e9040279561340516b881 | 7781c38552e6cc54ed8e9040279561340516b881 |
| linux | linux | >= e21b7a0b988772e82e7147e1c659a5afe2ae003c < 075a53b78b815301f8d3dd1ee2cd99554e34f0dd | 075a53b78b815301f8d3dd1ee2cd99554e34f0dd |
| linux | linux_kernel | >= 0 < 5.10.127-1 | 5.10.127-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 4.12 < 5.4.198 | 5.4.198 |
| linux | linux_kernel | >= 5.11 < 5.15.46 | 5.15.46 |
| linux | linux_kernel | >= 5.16 < 5.17.14 | 5.17.14 |
| linux | linux_kernel | >= 5.18 < 5.18.3 | 5.18.3 |
| linux | linux_kernel | >= 5.5 < 5.10.121 | 5.10.121 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wx6q-q8rv-cm38: In the Linux kernel, the following vulnerability has been resolved:
bfq: Make sure bfqg for which we are queueing requests is online
Bios queued int
ghsa_unreviewed·2025-03-06
CVE-2022-49411 [HIGH] CWE-416 GHSA-wx6q-q8rv-cm38: In the Linux kernel, the following vulnerability has been resolved:
bfq: Make sure bfqg for which we are queueing requests is online
Bios queued int
In the Linux kernel, the following vulnerability has been resolved:
bfq: Make sure bfqg for which we are queueing requests is online
Bios queued into BFQ IO scheduler can be associated with a cgroup that
was already offlined. This may then cause insertion of this bfq_group
into a service tree. But this bfq_group will get freed as soon as last
bio associated with it is completed leading to use after free issues for
service tree users. Fix the problem by making sure we always operate on
online bfq_group. If the bfq_group associated with the bio is not
online, we pick the first online parent.
OSV
CVE-2022-49411: In the Linux kernel, the following vulnerability has been resolved: bfq: Make sure bfqg for which we are queueing requests is online Bios queued into
osv·2025-02-26·CVSS 7.8
CVE-2022-49411 [HIGH] CVE-2022-49411: In the Linux kernel, the following vulnerability has been resolved: bfq: Make sure bfqg for which we are queueing requests is online Bios queued into
In the Linux kernel, the following vulnerability has been resolved: bfq: Make sure bfqg for which we are queueing requests is online Bios queued into BFQ IO scheduler can be associated with a cgroup that was already offlined. This may then cause insertion of this bfq_group into a service tree. But this bfq_group will get freed as soon as last bio associated with it is completed leading to use after free issues for service tree users. Fix the problem by making sure we always operate on online bfq_group. If the bfq_group associated with the bio is not online, we pick the first online parent.
Red Hat
kernel: bfq: Make sure bfqg for which we are queueing requests is online
vendor_redhat·2025-02-26·CVSS 7.8
CVE-2022-49411 [HIGH] CWE-99 kernel: bfq: Make sure bfqg for which we are queueing requests is online
kernel: bfq: Make sure bfqg for which we are queueing requests is online
In the Linux kernel, the following vulnerability has been resolved:
bfq: Make sure bfqg for which we are queueing requests is online
Bios queued into BFQ IO scheduler can be associated with a cgroup that
was already offlined. This may then cause insertion of this bfq_group
into a service tree. But this bfq_group will get freed as soon as last
bio associated with it is completed leading to use after free issues for
service tree users. Fix the problem by making sure we always operate on
online bfq_group. If the bfq_group associated with the bio is not
online, we pick the first online parent.
A use-after-free vulnerability exists in the Linux kernel. The Bios queued into the BFQ IO scheduler can be associated with a cg
Debian
CVE-2022-49411: linux - In the Linux kernel, the following vulnerability has been resolved: bfq: Make s...
vendor_debian·2022·CVSS 7.8
CVE-2022-49411 [HIGH] CVE-2022-49411: linux - In the Linux kernel, the following vulnerability has been resolved: bfq: Make s...
In the Linux kernel, the following vulnerability has been resolved: bfq: Make sure bfqg for which we are queueing requests is online Bios queued into BFQ IO scheduler can be associated with a cgroup that was already offlined. This may then cause insertion of this bfq_group into a service tree. But this bfq_group will get freed as soon as last bio associated with it is completed leading to use after free issues for service tree users. Fix the problem by making sure we always operate on online bfq_group. If the bfq_group associated with the bio is not online, we pick the first online parent.
Scope: local
bookworm: resolved (fixed in 5.18.5-1)
bullseye: resolved (fixed in 5.10.127-1)
forky: resolved (fixed in 5.18.5-1)
sid: resolved (fixed in 5.18.5-1)
trixie: resolved (fixed in 5.18.5-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/075a53b78b815301f8d3dd1ee2cd99554e34f0ddhttps://git.kernel.org/stable/c/51f724bffa3403a5236597e6b75df7329c1ec6e9https://git.kernel.org/stable/c/6ee0868b0c3ccead5907685fcdcdd0c08dfe4b0bhttps://git.kernel.org/stable/c/7781c38552e6cc54ed8e9040279561340516b881https://git.kernel.org/stable/c/97bd6c56bdcb41079e488e31df56809e3b2ce628https://git.kernel.org/stable/c/ccddf8cd411c1800863ed357064e56ceffd356bb
2025-02-26
Published