Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-49327— bcache: avoid journal no-space deadlock by reserving 1 journal bucket

AI Predicted 5.3 Difficulty: Moderate EPSS 0.19% · P9

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinuxcafe563591446cf80bfbc2fe3bc72a2e36cf1060< 59afd4f287900c8187e968a4153ed35e6b48efceaffected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< 5607652823ac65e2c6885e73bd46d5a4f9a20363affected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< 6332ea3e35efa12dc08f0cbf5faea5e6e8eb0497affected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< 1dda32aed6f62c163f38ff947ef5b3360e329159affected
cafe563591446cf80bfbc2fe3bc72a2e36cf1060< 32feee36c30ea06e38ccb8ae6e5c44c6eec790a6affected
3.10affected
< 3.10unaffected
5.10.121≤ 5.10.*unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-49327

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
bcache: avoid journal no-space deadlock by reserving 1 journal bucket
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bcache: avoid journal no-space deadlock by reserving 1 journal bucket The journal no-space deadlock was reported time to time. Such deadlock can happen in the following situation. When all journal buckets are fully filled by active jset with heavy write I/O load, the cache set registration (after a reboot) will load all active jsets and inserting them into the btree again (which is called journal replay). If a journaled bkey is inserted into a btree node and results btree node split, new journal request might be triggered. For example, the btree grows one more level after the node split, then the root node record in cache device super block will be upgrade by bch_journal_meta() from bch_btree_set_root(). But there is no space in journal buckets, the journal replay has to wait for new journal bucket to be reclaimed after at least one journal bucket replayed. This is one example that how the journal no-space deadlock happens. The solution to avoid the deadlock is to reserve 1 journal bucket in run time, and only permit the reserved journal bucket to be used during cache set registration procedure for things like journal replay. Then the journal space will never be fully filled, there is no chance for journal no-space deadlock to happen anymore. This patch adds a new member "bool do_reserve" in struct journal, it is inititalized to 0 (false) when struct journal is allocated, and set to 1 (true) by bch_journal_space_reserve() when all initialization done in run_cache_set(). In the run time when journal_reclaim() tries to allocate a new journal bucket, free_journal_buckets() is called to check whether there are enough free journal buckets to use. If there is only 1 free journal bucket and journal->do_reserve is 1 (true), the last bucket is reserved and free_journal_buckets() will return 0 to indicate no free journal bucket. Then journal_reclaim() will give up, and try next time to see whetheer there is free journal bucket to allocate. By this method, there is always 1 jouranl bucket reserved in run time. During the cache set registration, journal->do_reserve is 0 (false), so the reserved journal bucket can be used to avoid the no-space deadlock.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于bcache在日志空间不足时可能发生死锁。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux cafe563591446cf80bfbc2fe3bc72a2e36cf1060 ~ 59afd4f287900c8187e968a4153ed35e6b48efce -
LinuxLinux 3.10 -

II. Public POCs for CVE-2022-49327

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-49327

登录查看更多情报信息。

Patches & Fixes for CVE-2022-49327 (5)

Same Patch Batch · Linux · 2025-02-26 · 706 CVEs total

CVE-2022-491499.8 CRITICALrxrpc: Fix call timer start racing with call destruction
CVE-2022-495619.8 CRITICALnetfilter: conntrack: re-fetch conntrack after insertion
CVE-2022-494079.8 CRITICALdlm: fix plock invalid read
CVE-2022-493629.8 CRITICALNFSD: Fix potential use-after-free in nfsd_file_put()
CVE-2022-492809.8 CRITICALNFSD: prevent underflow in nfssvc_decode_writeargs()
CVE-2022-493569.8 CRITICALSUNRPC: Trap RDMA segment overflows
CVE-2022-494189.8 CRITICALNFSv4: Fix free of uninitialized nfs4_label on referral lookup.
CVE-2022-490949.8 CRITICALnet/tls: fix slab-out-of-bounds bug in decrypt_internal
CVE-2022-490939.8 CRITICALskbuff: fix coalescing for page_pool fragment recycling
CVE-2022-492609.8 CRITICALcrypto: hisilicon/sec - fix the aead software fallback for engine
CVE-2022-491949.8 CRITICALnet: bcmgenet: Use stronger register read/writes to assure ordering
CVE-2022-492019.8 CRITICALibmvnic: fix race between xmit and reset
CVE-2022-490589.1 CRITICALcifs: potential buffer overflow in handling symlinks
CVE-2022-495358.8 HIGHscsi: lpfc: Fix null pointer dereference after failing to issue FLOGI and PLOGI
CVE-2022-491598.8 HIGHscsi: qla2xxx: Implement ref count for SRB
CVE-2022-491388.8 HIGHBluetooth: hci_event: Ignore multiple conn complete events
CVE-2022-494798.8 HIGHmt76: fix tx status related use-after-free race on station removal
CVE-2022-494708.8 HIGHBluetooth: btmtksdio: fix use-after-free at btmtksdio_recv_event
CVE-2022-491118.8 HIGHBluetooth: Fix use after free in hci_send_acl
CVE-2022-491148.8 HIGHscsi: libfc: Fix use after free in fc_exch_abts_resp()

Showing top 20 of 706 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-49327

No comments yet


Leave a comment