CVE-2022-49179
Detail
Description
In the Linux kernel, the following vulnerability has been resolved:
block, bfq: don't move oom_bfqq
Our test report a UAF:
[ 2073.019181] ==================================================================
[ 2073.019188] BUG: KASAN: use-after-free in __bfq_put_async_bfqq+0xa0/0x168
[ 2073.019191] Write of size 8 at addr ffff8000ccf64128 by task rmmod/72584
[ 2073.019192]
[ 2073.019196] CPU: 0 PID: 72584 Comm: rmmod Kdump: loaded Not tainted 4.19.90-yk #5
[ 2073.019198] Hardware name: QEMU KVM Virtual Machine, BIOS 0.0.0 02/06/2015
[ 2073.019200] Call trace:
[ 2073.019203] dump_backtrace+0x0/0x310
[ 2073.019206] show_stack+0x28/0x38
[ 2073.019210] dump_stack+0xec/0x15c
[ 2073.019216] print_address_description+0x68/0x2d0
[ 2073.019220] kasan_report+0x238/0x2f0
[ 2073.019224] __asan_store8+0x88/0xb0
[ 2073.019229] __bfq_put_async_bfqq+0xa0/0x168
[ 2073.019233] bfq_put_async_queues+0xbc/0x208
[ 2073.019236] bfq_pd_offline+0x178/0x238
[ 2073.019240] blkcg_deactivate_policy+0x1f0/0x420
[ 2073.019244] bfq_exit_queue+0x128/0x178
[ 2073.019249] blk_mq_exit_sched+0x12c/0x160
[ 2073.019252] elevator_exit+0xc8/0xd0
[ 2073.019256] blk_exit_queue+0x50/0x88
[ 2073.019259] blk_cleanup_queue+0x228/0x3d8
[ 2073.019267] null_del_dev+0xfc/0x1e0 [null_blk]
[ 2073.019274] null_exit+0x90/0x114 [null_blk]
[ 2073.019278] __arm64_sys_delete_module+0x358/0x5a0
[ 2073.019282] el0_svc_common+0xc8/0x320
[ 2073.019287] el0_svc_handler+0xf8/0x160
[ 2073.019290] el0_svc+0x10/0x218
[ 2073.019291]
[ 2073.019294] Allocated by task 14163:
[ 2073.019301] kasan_kmalloc+0xe0/0x190
[ 2073.019305] kmem_cache_alloc_node_trace+0x1cc/0x418
[ 2073.019308] bfq_pd_alloc+0x54/0x118
[ 2073.019313] blkcg_activate_policy+0x250/0x460
[ 2073.019317] bfq_create_group_hierarchy+0x38/0x110
[ 2073.019321] bfq_init_queue+0x6d0/0x948
[ 2073.019325] blk_mq_init_sched+0x1d8/0x390
[ 2073.019330] elevator_switch_mq+0x88/0x170
[ 2073.019334] elevator_switch+0x140/0x270
[ 2073.019338] elv_iosched_store+0x1a4/0x2a0
[ 2073.019342] queue_attr_store+0x90/0xe0
[ 2073.019348] sysfs_kf_write+0xa8/0xe8
[ 2073.019351] kernfs_fop_write+0x1f8/0x378
[ 2073.019359] __vfs_write+0xe0/0x360
[ 2073.019363] vfs_write+0xf0/0x270
[ 2073.019367] ksys_write+0xdc/0x1b8
[ 2073.019371] __arm64_sys_write+0x50/0x60
[ 2073.019375] el0_svc_common+0xc8/0x320
[ 2073.019380] el0_svc_handler+0xf8/0x160
[ 2073.019383] el0_svc+0x10/0x218
[ 2073.019385]
[ 2073.019387] Freed by task 72584:
[ 2073.019391] __kasan_slab_free+0x120/0x228
[ 2073.019394] kasan_slab_free+0x10/0x18
[ 2073.019397] kfree+0x94/0x368
[ 2073.019400] bfqg_put+0x64/0xb0
[ 2073.019404] bfqg_and_blkg_put+0x90/0xb0
[ 2073.019408] bfq_put_queue+0x220/0x228
[ 2073.019413] __bfq_put_async_bfqq+0x98/0x168
[ 2073.019416] bfq_put_async_queues+0xbc/0x208
[ 2073.019420] bfq_pd_offline+0x178/0x238
[ 2073.019424] blkcg_deactivate_policy+0x1f0/0x420
[ 2073.019429] bfq_exit_queue+0x128/0x178
[ 2073.019433] blk_mq_exit_sched+0x12c/0x160
[ 2073.019437] elevator_exit+0xc8/0xd0
[ 2073.019440] blk_exit_queue+0x50/0x88
[ 2073.019443] blk_cleanup_queue+0x228/0x3d8
[ 2073.019451] null_del_dev+0xfc/0x1e0 [null_blk]
[ 2073.019459] null_exit+0x90/0x114 [null_blk]
[ 2073.019462] __arm64_sys_delete_module+0x358/0x5a0
[ 2073.019467] el0_svc_common+0xc8/0x320
[ 2073.019471] el0_svc_handler+0xf8/0x160
[ 2073.019474] el0_svc+0x10/0x218
[ 2073.019475]
[ 2073.019479] The buggy address belongs to the object at ffff8000ccf63f00
which belongs to the cache kmalloc-1024 of size 1024
[ 2073.019484] The buggy address is located 552 bytes inside of
1024-byte region [ffff8000ccf63f00, ffff8000ccf64300)
[ 2073.019486] The buggy address belongs to the page:
[ 2073.019492] page:ffff7e000333d800 count:1 mapcount:0 mapping:ffff8000c0003a00 index:0x0 compound_mapcount: 0
[ 2073.020123] flags: 0x7ffff0000008100(slab|head)
[ 2073.020403] raw: 07ffff0000008100 ffff7e0003334c08 ffff7e00001f5a08 ffff8000c0003a00
[ 2073.020409] ra
---truncated---
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 4.0 Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 3.x Severity and Vector Strings:
NVD assessment
not yet provided.
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.0 Severity and Vector Strings:
NVD assessment
not yet provided.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected] .
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-416
Use After Free
CISA-ADP
Change History
6 change records found show changes
CVE Modified by kernel.org
8/12/2026 8:17:30 PM
Action
Type
Old Value
New Value
Added
CVSS V3.1
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Changed
Affected
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["block/bfq-cgroup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"aee69d78dec0ffdf82e35d57c626e80dddc314d5","lessThan":"c4f5a678add58a8a0e7ee5e038496b376ea6d205","versionType":"git","status":"affected"},{"version":"aee69d78dec0ffdf82e35d57c626e80dddc314d5","lessThan":"7507ead1e9d42957c2340f2c4a0e9d00034e3366","versionType":"git","status":"affected"},{"version":"aee69d78dec0ffdf82e35d57c626e80dddc314d5","lessThan":"8f34dea99cd7761156a146a5258a67d045d862f7","versionType":"git","status":"affected"},{"version":"aee69d78dec0ffdf82e35d57c626e80dddc314d5","lessThan":"87fdfe8589d43e471dffb4c60f75eeb6f37afc4c","versionType":"git","status":"affected"},{"version":"aee69d78dec0ffdf82e35d57c626e80dddc314d5","lessThan":"c01fced8d38fbccc82787065229578006f28e020","versionType":"git","status":"affected"},{"version":"aee69d78dec0ffdf82e35d57c626e80dddc314d5","lessThan":"8410f70977734f21b8ed45c37e925d311dfda2e7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["block/bfq-cgroup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.4.189","lessThanOrEqual":"5.4.*","versionType":"semver","status":"unaffected"},{"version":"5.10.110","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.33","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"5.16.19","lessThanOrEqual":"5.16.*","versionType":"semver","status":"unaffected"},{"version":"5.17.2","lessThanOrEqual":"5.17.*","versionType":"semver","status":"unaffected"},{"version":"5.18","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["block/bfq-cgroup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0d52af590552473666da5b6111e7182d6cd23f92","lessThan":"c4f5a678add58a8a0e7ee5e038496b376ea6d205","versionType":"git","status":"affected"},{"version":"0d52af590552473666da5b6111e7182d6cd23f92","lessThan":"7507ead1e9d42957c2340f2c4a0e9d00034e3366","versionType":"git","status":"affected"},{"version":"0d52af590552473666da5b6111e7182d6cd23f92","lessThan":"8f34dea99cd7761156a146a5258a67d045d862f7","versionType":"git","status":"affected"},{"version":"0d52af590552473666da5b6111e7182d6cd23f92","lessThan":"87fdfe8589d43e471dffb4c60f75eeb6f37afc4c","versionType":"git","status":"affected"},{"version":"0d52af590552473666da5b6111e7182d6cd23f92","lessThan":"c01fced8d38fbccc82787065229578006f28e020","versionType":"git","status":"affected"},{"version":"0d52af590552473666da5b6111e7182d6cd23f92","lessThan":"8410f70977734f21b8ed45c37e925d311dfda2e7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["block/bfq-cgroup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.16","status":"affected"},{"version":"0","lessThan":"4.16","versionType":"semver","status":"unaffected"},{"version":"5.4.189","lessThanOrEqual":"5.4.*","versionType":"semver","status":"unaffected"},{"version":"5.10.110","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.33","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"5.16.19","lessThanOrEqual":"5.16.*","versionType":"semver","status":"unaffected"},{"version":"5.17.2","lessThanOrEqual":"5.17.*","versionType":"semver","status":"unaffected"},{"version":"5.18","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]
CVE Modified by CISA-ADP
6/17/2026 1:17:17 AM
Action
Type
Old Value
New Value
Added
SSVC
{"timestamp":"2025-02-27T17:59:03.662860Z","id":"CVE-2022-49179","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}
CVE Modified by kernel.org
6/17/2026 1:17:17 AM
Action
Type
Old Value
New Value
Added
Affected
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["block/bfq-cgroup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"aee69d78dec0ffdf82e35d57c626e80dddc314d5","lessThan":"c4f5a678add58a8a0e7ee5e038496b376ea6d205","versionType":"git","status":"affected"},{"version":"aee69d78dec0ffdf82e35d57c626e80dddc314d5","lessThan":"7507ead1e9d42957c2340f2c4a0e9d00034e3366","versionType":"git","status":"affected"},{"version":"aee69d78dec0ffdf82e35d57c626e80dddc314d5","lessThan":"8f34dea99cd7761156a146a5258a67d045d862f7","versionType":"git","status":"affected"},{"version":"aee69d78dec0ffdf82e35d57c626e80dddc314d5","lessThan":"87fdfe8589d43e471dffb4c60f75eeb6f37afc4c","versionType":"git","status":"affected"},{"version":"aee69d78dec0ffdf82e35d57c626e80dddc314d5","lessThan":"c01fced8d38fbccc82787065229578006f28e020","versionType":"git","status":"affected"},{"version":"aee69d78dec0ffdf82e35d57c626e80dddc314d5","lessThan":"8410f70977734f21b8ed45c37e925d311dfda2e7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["block/bfq-cgroup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.4.189","lessThanOrEqual":"5.4.*","versionType":"semver","status":"unaffected"},{"version":"5.10.110","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.33","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"5.16.19","lessThanOrEqual":"5.16.*","versionType":"semver","status":"unaffected"},{"version":"5.17.2","lessThanOrEqual":"5.17.*","versionType":"semver","status":"unaffected"},{"version":"5.18","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]
Initial Analysis by NIST
3/25/2025 11:07:03 AM
Action
Type
Old Value
New Value
Added
CPE Configuration
OR
*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.33
*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.17 up to (excluding) 5.17.2
*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.5 up to (excluding) 5.10.110
*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 5.16.19
*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to (excluding) 5.4.189
Added
Reference Type
kernel.org: https://git.kernel.org/stable/c/7507ead1e9d42957c2340f2c4a0e9d00034e3366 Types: Patch
Added
Reference Type
kernel.org: https://git.kernel.org/stable/c/8410f70977734f21b8ed45c37e925d311dfda2e7 Types: Patch
Added
Reference Type
kernel.org: https://git.kernel.org/stable/c/87fdfe8589d43e471dffb4c60f75eeb6f37afc4c Types: Patch
Added
Reference Type
kernel.org: https://git.kernel.org/stable/c/8f34dea99cd7761156a146a5258a67d045d862f7 Types: Patch
Added
Reference Type
kernel.org: https://git.kernel.org/stable/c/c01fced8d38fbccc82787065229578006f28e020 Types: Patch
Added
Reference Type
kernel.org: https://git.kernel.org/stable/c/c4f5a678add58a8a0e7ee5e038496b376ea6d205 Types: Patch
CVE Modified by CISA-ADP
2/27/2025 1:15:24 PM
Action
Type
Old Value
New Value
Added
CVSS V3.1
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Added
CWE
CWE-416
New CVE Received from kernel.org
2/26/2025 2:00:55 AM
Action
Type
Old Value
New Value
Added
Description
Record truncated, showing 2048 of 3998 characters.
View Entire Change Record
In the Linux kernel, the following vulnerability has been resolved:
block, bfq: don't move oom_bfqq
Our test report a UAF:
[ 2073.019181] ==================================================================
[ 2073.019188] BUG: KASAN: use-after-free in __bfq_put_async_bfqq+0xa0/0x168
[ 2073.019191] Write of size 8 at addr ffff8000ccf64128 by task rmmod/72584
[ 2073.019192]
[ 2073.019196] CPU: 0 PID: 72584 Comm: rmmod Kdump: loaded Not tainted 4.19.90-yk #5
[ 2073.019198] Hardware name: QEMU KVM Virtual Machine, BIOS 0.0.0 02/06/2015
[ 2073.019200] Call trace:
[ 2073.019203] dump_backtrace+0x0/0x310
[ 2073.019206] show_stack+0x28/0x38
[ 2073.019210] dump_stack+0xec/0x15c
[ 2073.019216] print_address_description+0x68/0x2d0
[ 2073.019220] kasan_report+0x238/0x2f0
[ 2073.019224] __asan_store8+0x88/0xb0
[ 2073.019229] __bfq_put_async_bfqq+0xa0/0x168
[ 2073.019233] bfq_put_async_queues+0xbc/0x208
[ 2073.019236] bfq_pd_offline+0x178/0x238
[ 2073.019240] blkcg_deactivate_policy+0x1f0/0x420
[ 2073.019244] bfq_exit_queue+0x128/0x178
[ 2073.019249] blk_mq_exit_sched+0x12c/0x160
[ 2073.019252] elevator_exit+0xc8/0xd0
[ 2073.019256] blk_exit_queue+0x50/0x88
[ 2073.019259] blk_cleanup_queue+0x228/0x3d8
[ 2073.019267] null_del_dev+0xfc/0x1e0 [null_blk]
[ 2073.019274] null_exit+0x90/0x114 [null_blk]
[ 2073.019278] __arm64_sys_delete_module+0x358/0x5a0
[ 2073.019282] el0_svc_common+0xc8/0x320
[ 2073.019287] el0_svc_handler+0xf8/0x160
[ 2073.019290] el0_svc+0x10/0x218
[ 2073.019291]
[ 2073.019294] Allocated by task 14163:
[ 2073.019301] kasan_kmalloc+0xe0/0x190
[ 2073.019305] kmem_cache_alloc_node_trace+0x1cc/0x418
[ 2073.019308] bfq_pd_alloc+0x54/0x118
[ 2073.019313] blkcg_activate_policy+0x250/0x460
[ 2073.019317] bfq_create_group_hierarchy+0x38/0x110
[ 2073.019321] bfq_init_queue+0x6d0/0x948
[ 2073.019325] blk_mq_init_sched+0x1d8/0x390
[ 2073.019330] elevator_switch_mq+0x88/0x170
[ 2073.019334] elevator_switch+0x140/0x270
[ 2073.019338] elv_iosched_store+0x1a4/0x2a0
[ 2073.019342] queue_attr_stor
Added
Reference
https://git.kernel.org/stable/c/7507ead1e9d42957c2340f2c4a0e9d00034e3366
Added
Reference
https://git.kernel.org/stable/c/8410f70977734f21b8ed45c37e925d311dfda2e7
Added
Reference
https://git.kernel.org/stable/c/87fdfe8589d43e471dffb4c60f75eeb6f37afc4c
Added
Reference
https://git.kernel.org/stable/c/8f34dea99cd7761156a146a5258a67d045d862f7
Added
Reference
https://git.kernel.org/stable/c/c01fced8d38fbccc82787065229578006f28e020
Added
Reference
https://git.kernel.org/stable/c/c4f5a678add58a8a0e7ee5e038496b376ea6d205
Quick Info
CVE Dictionary Entry: CVE-2022-49179 NVD
Published Date: 02/26/2025 NVD
Last Modified: 08/12/2026
Source: kernel.org