block, bfq: fix possible uaf for 'bfqq->bic'
Summary
| CVE | CVE-2022-50488 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-10-04 16:15:45 UTC |
| Updated | 2026-08-04 10:18:17 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: block, bfq: fix possible uaf for 'bfqq->bic' Our test report a uaf for 'bfqq->bic' in 5.10: ================================================================== BUG: KASAN: use-after-free in bfq_select_queue+0x378/0xa30 CPU: 6 PID: 2318352 Comm: fsstress Kdump: loaded Not tainted 5.10.0-60.18.0.50.h602.kasan.eulerosv2r11.x86_64 #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.1-0-ga5cab58-20220320_160524-szxrtosci10000 04/01/2014 Call Trace: bfq_select_queue+0x378/0xa30 bfq_dispatch_request+0xe8/0x130 blk_mq_do_dispatch_sched+0x62/0xb0 __blk_mq_sched_dispatch_requests+0x215/0x2a0 blk_mq_sched_dispatch_requests+0x8f/0xd0 __blk_mq_run_hw_queue+0x98/0x180 __blk_mq_delay_run_hw_queue+0x22b/0x240 blk_mq_run_hw_queue+0xe3/0x190 blk_mq_sched_insert_requests+0x107/0x200 blk_mq_flush_plug_list+0x26e/0x3c0 blk_finish_plug+0x63/0x90 __iomap_dio_rw+0x7b5/0x910 iomap_dio_rw+0x36/0x80 ext4_dio_read_iter+0x146/0x190 [ext4] ext4_file_read_iter+0x1e2/0x230 [ext4] new_sync_read+0x29f/0x400 vfs_read+0x24e/0x2d0 ksys_read+0xd5/0x1b0 do_syscall_64+0x33/0x40 entry_SYSCALL_64_after_hwframe+0x61/0xc6 Commit 3bc5e683c67d ("bfq: Split shared queues on move between cgroups") changes that move process to a new cgroup will allocate a new bfqq to use, however, the old bfqq and new bfqq can point to the same bic: 1) Initial state, two process with io in the same cgroup. Process 1 Process 2 (BIC1) (BIC2) | Λ | Λ | | | | V | V | bfqq1 bfqq2 2) bfqq1 is merged to bfqq2. Process 1 Process 2 (BIC1) (BIC2) | | \-------------\| V bfqq1 bfqq2(coop) 3) Process 1 exit, then issue new io(denoce IOA) from Process 2. (BIC2) | Λ | | V | bfqq2(coop) 4) Before IOA is completed, move Process 2 to another cgroup and issue io. Process 2 (BIC2) Λ |\--------------\ | V bfqq2 bfqq3 Now that BIC2 points to bfqq3, while bfqq2 and bfqq3 both point to BIC2. If all the requests are completed, and Process 2 exit, BIC2 will be freed while there is no guarantee that bfqq2 will be freed before BIC2. Fix the problem by clearing bfqq->bic while bfqq is detached from bic. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-416
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 4dfc12f8c94c8052e975060f595938f75e8b7165 5533742c7cb1bc9b1f0bf401cc397d44a3a9e07a git | Not specified |
| CNA | Linux | Linux | affected 81b7d0c717a487ec50e2924a773ff501ee40f0d5 094f3d9314d67691cb21ba091c1b528f6e3c4893 git | Not specified |
| CNA | Linux | Linux | affected 3bc5e683c67d94bd839a1da2e796c15847b51b69 b22fd72bfebda3956efc4431b60ddfc0a51e03e0 git | Not specified |
| CNA | Linux | Linux | affected 3bc5e683c67d94bd839a1da2e796c15847b51b69 761564d93c8265f65543acf0a576b32d66bfa26a git | Not specified |
| CNA | Linux | Linux | affected 3bc5e683c67d94bd839a1da2e796c15847b51b69 64dc8c732f5c2b406cc752e6aaa1bd5471159cab git | Not specified |
| CNA | Linux | Linux | affected 31326bf551269fb9bafa84ca99172b8340e5d8f8 git | Not specified |
| CNA | Linux | Linux | affected 43c51b86dbe551cff5d39b88aa2f41d29479f9c4 git | Not specified |
| CNA | Linux | Linux | affected 8615f6c0c9e7cf0ca90b6b5408784d797cbe5621 git | Not specified |
| CNA | Linux | Linux | affected 5.10.121 5.10.175 semver | Not specified |
| CNA | Linux | Linux | affected 5.15.46 5.15.86 semver | Not specified |
| CNA | Linux | Linux | affected 5.4.198 5.5 semver | Not specified |
| CNA | Linux | Linux | affected 5.17.14 5.18 semver | Not specified |
| CNA | Linux | Linux | affected 5.18.3 5.19 semver | Not specified |
| CNA | Linux | Linux | affected 5.19 | Not specified |
| CNA | Linux | Linux | unaffected 5.19 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.175 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.86 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.0.16 6.0.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.2 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/64dc8c732f5c2b406cc752e6aaa1bd5471159cab | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/761564d93c8265f65543acf0a576b32d66bfa26a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/b22fd72bfebda3956efc4431b60ddfc0a51e03e0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/5533742c7cb1bc9b1f0bf401cc397d44a3a9e07a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/094f3d9314d67691cb21ba091c1b528f6e3c4893 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.