CVE-2022-49033

EUVD-2022-53917
In the Linux kernel, the following vulnerability has been resolved:

btrfs: qgroup: fix sleep from invalid context bug in btrfs_qgroup_inherit()

Syzkaller reported BUG as follows:

  BUG: sleeping function called from invalid context at
       include/linux/sched/mm.h:274
  Call Trace:
   <TASK>
   dump_stack_lvl+0xcd/0x134
   __might_resched.cold+0x222/0x26b
   kmem_cache_alloc+0x2e7/0x3c0
   update_qgroup_limit_item+0xe1/0x390
   btrfs_qgroup_inherit+0x147b/0x1ee0
   create_subvol+0x4eb/0x1710
   btrfs_mksubvol+0xfe5/0x13f0
   __btrfs_ioctl_snap_create+0x2b0/0x430
   btrfs_ioctl_snap_create_v2+0x25a/0x520
   btrfs_ioctl+0x2a1c/0x5ce0
   __x64_sys_ioctl+0x193/0x200
   do_syscall_64+0x35/0x80

Fix this by calling qgroup_dirty() on @dstqgroup, and update limit item in
btrfs_run_qgroups() later outside of the spinlock context.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
𝑥
< 4.14.301
linuxlinux_kernel
4.15 ≤
𝑥
< 4.19.268
linuxlinux_kernel
4.20 ≤
𝑥
< 5.4.226
linuxlinux_kernel
5.5 ≤
𝑥
< 5.10.158
linuxlinux_kernel
5.11 ≤
𝑥
< 5.15.82
linuxlinux_kernel
5.16 ≤
𝑥
< 6.0.12
linuxlinux_kernel
6.1:rc1
linuxlinux_kernel
6.1:rc2
linuxlinux_kernel
6.1:rc3
linuxlinux_kernel
6.1:rc4
linuxlinux_kernel
6.1:rc5
linuxlinux_kernel
6.1:rc6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.106-3
fixed
bookworm (security)
6.1.112-1
fixed
bullseye
5.10.223-1
fixed
bullseye (security)
5.10.226-1
fixed
sid
6.11.6-1
fixed
trixie
6.11.5-1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
cluster-md-kmp-default
suse enterprise server 12 SP5
4.12.14-122.244.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.91.1
fixed
dlm-kmp-default
suse enterprise server 12 SP5
4.12.14-122.244.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.91.1
fixed
gfs2-kmp-default
suse enterprise server 12 SP5
4.12.14-122.244.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.91.1
fixed
kernel-64kb
suse enterprise server 15 SP5
5.14.21-150500.55.91.1
fixed
kernel-default
suse enterprise server 12 SP5
4.12.14-122.244.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.91.1
fixed
kernel-default-base
suse enterprise server 12 SP5
4.12.14-122.244.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.91.1.150500.6.41.1
fixed
kernel-default-man
suse enterprise server 12 SP5
4.12.14-122.244.1
fixed
kernel-docs
suse enterprise server 15 SP5
5.14.21-150500.55.91.1
fixed
kernel-macros
suse enterprise server 12 SP5
4.12.14-122.244.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.91.1
fixed
kernel-obs-build
suse enterprise server 15 SP5
5.14.21-150500.55.91.1
fixed
kernel-source
suse enterprise server 12 SP5
4.12.14-122.244.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.91.1
fixed
kernel-syms
suse enterprise server 12 SP5
4.12.14-122.244.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.91.1
fixed
kernel-zfcpdump
suse enterprise server 15 SP5
5.14.21-150500.55.91.1
fixed
ocfs2-kmp-default
suse enterprise server 12 SP5
4.12.14-122.244.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.91.1
fixed
reiserfs-kmp-default
suse enterprise server 15 SP5
5.14.21-150500.55.91.1
fixed