PT-2024-11787 · Linux+3 · Linux Kernel+3
David Sterba
+1
·
Published
2022-01-20
·
Updated
2024-08-22
·
CVE-2022-48734
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A deadlock vulnerability has been found in the Linux kernel, specifically in the btrfs file system. The issue occurs when the quota disable ioctl starts a transaction before waiting for the qgroup rescan worker to complete, resulting in a circular dependency among the quota disable ioctl, the qgroup rescan worker, and other tasks with transactions. This can lead to an infinite wait and a deadlock. The vulnerability was discovered using the fstests test case btrfs/115 and a zoned null blk device. An example report of the deadlock is provided, showing tasks blocked for more than 122 seconds.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse