CVE-2022-49167

HIGH

Linux Kernel 5.16-5.16.18, 5.17-5.17.1 - Denial of Service via Btrfs Compressed Read Error Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: do not double complete bio on errors during compressed reads I hit some weird panics while fixing up the error handling from btrfs_lookup_bio_sums(). Turns out the compression path will complete the bio we use if we set up any of the compression bios and then return an error, and then btrfs_submit_data_bio() will also call bio_endio() on the bio. Fix this by making btrfs_submit_compressed_read() responsible for calling bio_endio() on the bio if there are any errors. Currently it was only doing it if we created the compression bios, otherwise it was depending on btrfs_submit_data_bio() to do the right thing. This creates the above problem, so fix up btrfs_submit_compressed_read() to always call bio_endio() in case of an error, and then simply return from btrfs_submit_data_bio() if we had to call btrfs_submit_compressed_read().

Scores

CVSS v3 7.8
EPSS 0.0027
EPSS Percentile 18.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (11)
linux/Kernel 5.16.0 - 5.16.19linux
linux/Kernel 5.17.0 - 5.17.2linux
Linux/Linux < 5.16
Linux/Linux 5.16
Linux/Linux 5.16.19 - 5.16.*
Linux/Linux 5.17.2 - 5.17.*
Linux/Linux 5.18
Linux/Linux 86ccbb4d2a2af4109430df518c995a4f7d14dfd2 - 4a4ceb2b990771c374d85d496a1a45255dde48e3
Linux/Linux 86ccbb4d2a2af4109430df518c995a4f7d14dfd2 - 987b5df1d10355d377315a26e7fb6c72ded83c9f
Linux/Linux 86ccbb4d2a2af4109430df518c995a4f7d14dfd2 - f9f15de85d74e7eef021af059ca53a15f041cdd8
... and 1 more
Published Feb 26, 2025
Tracked Since Feb 18, 2026