CVE-2022-49406

Source
https://cve.org/CVERecord?id=CVE-2022-49406
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49406.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-49406
Downstream
Related
Published
2025-02-26T02:12:31.086Z
Modified
2026-04-02T08:27:33.611291Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
block: Fix potential deadlock in blk_ia_range_sysfs_show()
Details

In the Linux kernel, the following vulnerability has been resolved:

block: Fix potential deadlock in blkiarangesysfsshow()

When being read, a sysfs attribute is already protected against removal with the kobject node active reference counter. As a result, in blkiarangesysfsshow(), there is no need to take the queue sysfs lock when reading the value of a range attribute. Using the queue sysfs lock in this function creates a potential deadlock situation with the disk removal, something that a lockdep signals with a splat when the device is removed:

[ 760.703551] Possible unsafe locking scenario: [ 760.703551] [ 760.703554] CPU0 CPU1 [ 760.703556] ---- ---- [ 760.703558] lock(&q->sysfslock); [ 760.703565] lock(kn->active#385); [ 760.703573] lock(&q->sysfslock); [ 760.703579] lock(kn->active#385); [ 760.703587] [ 760.703587] *** DEADLOCK ***

Solve this by removing the mutexlock()/mutexunlock() calls from blkiarangesysfsshow().

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49406.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a2247f19ee1c5ad75ef095cdfb909a3244b88aa8
Fixed
dc107c805cde709866b59867ef72b9390199205e
Fixed
717b078bc745ba9a262abebed9806a17e8bbb77b
Fixed
41e46b3c2aa24f755b2ae9ec4ce931ba5f0d8532

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49406.json"