Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-48920— btrfs: get rid of warning on transaction commit when using flushoncommit

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于__writeback_inodes_sb_nr函数中的WARN_ON条件不正确。

AI Predicted 5.3 Difficulty: Theoretical EPSS 0.16% · P6

Affected Version Matrix 8

VendorProduct Version RangeStatus
Linux Linux ce8ea7cc6eb3139f4c730d647325e69354159b0f< 850a77c999b81dd2724efd2684068d6f90db8c16 affected
ce8ea7cc6eb3139f4c730d647325e69354159b0f< e4d044dbffcd570351f21c747fc77ff90aed7f2e affected
ce8ea7cc6eb3139f4c730d647325e69354159b0f< a0f0cf8341e34e5d2265bfd3a7ad68342da1e2aa affected
4.15 affected
< 4.15 unaffected
5.15.27≤ 5.15.* unaffected
5.16.13≤ 5.16.* unaffected
5.17≤ * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-48920

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
btrfs: get rid of warning on transaction commit when using flushoncommit
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: btrfs: get rid of warning on transaction commit when using flushoncommit When using the flushoncommit mount option, during almost every transaction commit we trigger a warning from __writeback_inodes_sb_nr(): $ cat fs/fs-writeback.c: (...) static void __writeback_inodes_sb_nr(struct super_block *sb, ... { (...) WARN_ON(!rwsem_is_locked(&sb->s_umount)); (...) } (...) The trace produced in dmesg looks like the following: [947.473890] WARNING: CPU: 5 PID: 930 at fs/fs-writeback.c:2610 __writeback_inodes_sb_nr+0x7e/0xb3 [947.481623] Modules linked in: nfsd nls_cp437 cifs asn1_decoder cifs_arc4 fscache cifs_md4 ipmi_ssif [947.489571] CPU: 5 PID: 930 Comm: btrfs-transacti Not tainted 95.16.3-srb-asrock-00001-g36437ad63879 #186 [947.497969] RIP: 0010:__writeback_inodes_sb_nr+0x7e/0xb3 [947.502097] Code: 24 10 4c 89 44 24 18 c6 (...) [947.519760] RSP: 0018:ffffc90000777e10 EFLAGS: 00010246 [947.523818] RAX: 0000000000000000 RBX: 0000000000963300 RCX: 0000000000000000 [947.529765] RDX: 0000000000000000 RSI: 000000000000fa51 RDI: ffffc90000777e50 [947.535740] RBP: ffff888101628a90 R08: ffff888100955800 R09: ffff888100956000 [947.541701] R10: 0000000000000002 R11: 0000000000000001 R12: ffff888100963488 [947.547645] R13: ffff888100963000 R14: ffff888112fb7200 R15: ffff888100963460 [947.553621] FS: 0000000000000000(0000) GS:ffff88841fd40000(0000) knlGS:0000000000000000 [947.560537] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [947.565122] CR2: 0000000008be50c4 CR3: 000000000220c000 CR4: 00000000001006e0 [947.571072] Call Trace: [947.572354] <TASK> [947.573266] btrfs_commit_transaction+0x1f1/0x998 [947.576785] ? start_transaction+0x3ab/0x44e [947.579867] ? schedule_timeout+0x8a/0xdd [947.582716] transaction_kthread+0xe9/0x156 [947.585721] ? btrfs_cleanup_transaction.isra.0+0x407/0x407 [947.590104] kthread+0x131/0x139 [947.592168] ? set_kthread_struct+0x32/0x32 [947.595174] ret_from_fork+0x22/0x30 [947.597561] </TASK> [947.598553] ---[ end trace 644721052755541c ]--- This is because we started using writeback_inodes_sb() to flush delalloc when committing a transaction (when using -o flushoncommit), in order to avoid deadlocks with filesystem freeze operations. This change was made by commit ce8ea7cc6eb313 ("btrfs: don't call btrfs_start_delalloc_roots in flushoncommit"). After that change we started producing that warning, and every now and then a user reports this since the warning happens too often, it spams dmesg/syslog, and a user is unsure if this reflects any problem that might compromise the filesystem's reliability. We can not just lock the sb->s_umount semaphore before calling writeback_inodes_sb(), because that would at least deadlock with filesystem freezing, since at fs/super.c:freeze_super() sync_filesystem() is called while we are holding that semaphore in write mode, and that can trigger a transaction commit, resulting in a deadlock. It would also trigger the same type of deadlock in the unmount path. Possibly, it could also introduce some other locking dependencies that lockdep would report. To fix this call try_to_writeback_inodes_sb() instead of writeback_inodes_sb(), because that will try to read lock sb->s_umount and then will only call writeback_inodes_sb() if it was able to lock it. This is fine because the cases where it can't read lock sb->s_umount are during a filesystem unmount or during a filesystem freeze - in those cases sb->s_umount is write locked and sync_filesystem() is called, which calls writeback_inodes_sb(). In other words, in all cases where we can't take a read lock on sb->s_umount, writeback is already being triggered elsewhere. An alternative would be to call btrfs_start_delalloc_roots() with a number of pages different from LONG_MAX, for example matching the number of delalloc bytes we currently have, in ---truncated---
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于__writeback_inodes_sb_nr函数中的WARN_ON条件不正确。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux ce8ea7cc6eb3139f4c730d647325e69354159b0f ~ 850a77c999b81dd2724efd2684068d6f90db8c16 -
Linux Linux 4.15 -

II. Public POCs for CVE-2022-48920

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-48920

登录查看更多情报信息。

Other References for CVE-2022-48920 (3)

Same Patch Batch · Linux · 2024-08-22 · 42 CVEs total

CVE-2022-48941 8.8 HIGH ice: fix concurrent reset and removal of VFs
CVE-2022-48919 8.8 HIGH cifs: fix double free race when mount fails in cifs_get_root()
CVE-2022-48925 7.8 HIGH RDMA/cma: Do not change route.addr.src_addr outside state checks
CVE-2022-48923 7.8 HIGH btrfs: prevent copying too big compressed lzo segment
CVE-2022-48927 7.8 HIGH iio: adc: tsc2046: fix memory corruption by preventing array overflow
CVE-2022-48913 7.8 HIGH blktrace: fix use after free for struct blk_trace
CVE-2022-48912 7.8 HIGH netfilter: fix use-after-free in __nf_register_net_hook()
CVE-2022-48911 7.8 HIGH netfilter: nf_queue: fix possible use-after-free
CVE-2022-48932 7.8 HIGH net/mlx5: DR, Fix slab-out-of-bounds in mlx5_cmd_dr_create_fte
CVE-2022-48935 7.8 HIGH netfilter: nf_tables: unregister flowtable hooks on netns exit
CVE-2022-48940 7.8 HIGH bpf: Fix crash due to incorrect copy_map_value
CVE-2022-48943 7.1 HIGH KVM: x86/mmu: make apf token non-zero to fix bug
CVE-2022-48933 netfilter: nf_tables: fix memory leak during stateful obj update
CVE-2022-48931 configfs: fix a race in configfs_{,un}register_subsystem()
CVE-2022-48934 nfp: flower: Fix a potential leak in nfp_tunnel_add_shared_mac()
CVE-2022-48937 io_uring: add a schedule point in io_add_buffers()
CVE-2022-48930 RDMA/ib_srp: Fix a deadlock
CVE-2022-48929 bpf: Fix crash due to out of bounds access into reg2btf_ids.
CVE-2022-48928 iio: adc: men_z188_adc: Fix a resource leak in an error handling path
CVE-2022-48938 CDC-NCM: avoid overflow in sanity checking

Showing top 20 of 42 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-48920

No comments yet


Leave a comment