CVE-2022-49720

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-49720
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49720.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-49720
Downstream
Related
Published
2025-02-26T02:24:34Z
Modified
2025-10-15T00:09:50.295839Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
block: Fix handling of offline queues in blk_mq_alloc_request_hctx()
Details

In the Linux kernel, the following vulnerability has been resolved:

block: Fix handling of offline queues in blkmqallocrequesthctx()

This patch prevents that test nvme/004 triggers the following:

UBSAN: array-index-out-of-bounds in block/blk-mq.h:135:9 index 512 is out of range for type 'long unsigned int [512]' Call Trace: showstack+0x52/0x58 dumpstacklvl+0x49/0x5e dumpstack+0x10/0x12 ubsanepilogue+0x9/0x3b _ubsanhandleoutofbounds.cold+0x44/0x49 blkmqallocrequesthctx+0x304/0x310 _nvmesubmitsynccmd+0x70/0x200 [nvmecore] nvmfconnectioqueue+0x23e/0x2a0 [nvmefabrics] nvmeloopconnectioqueues+0x8d/0xb0 [nvmeloop] nvmeloopcreatectrl+0x58e/0x7d0 [nvmeloop] nvmfcreatectrl+0x1d7/0x4d0 [nvmefabrics] nvmfdevwrite+0xae/0x111 [nvmefabrics] vfswrite+0x144/0x560 ksyswrite+0xb7/0x140 _x64syswrite+0x42/0x50 dosyscall64+0x35/0x80 entrySYSCALL64after_hwframe+0x44/0xae

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
20e4d813931961fe26d26a1e98b3aba6ec00b130
Fixed
7fa28a7c3d74933a4fc22d341b60927952f31c19
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
20e4d813931961fe26d26a1e98b3aba6ec00b130
Fixed
b5e65ef044d627effdc2599040b6d204e003f955
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
20e4d813931961fe26d26a1e98b3aba6ec00b130
Fixed
b202a0bd2580ee5b0453772c46d464152fafff73
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
20e4d813931961fe26d26a1e98b3aba6ec00b130
Fixed
14dc7a18abbe4176f5626c13c333670da8e06aa1

Affected versions

v4.*

v4.15
v4.15-rc5
v4.15-rc6
v4.15-rc7
v4.15-rc8
v4.15-rc9
v4.16
v4.16-rc1
v4.16-rc2
v4.16-rc3
v4.16-rc4
v4.16-rc5
v4.16-rc6
v4.16-rc7
v4.17
v4.17-rc1
v4.17-rc2
v4.17-rc3
v4.17-rc4
v4.17-rc5
v4.17-rc6
v4.17-rc7
v4.18
v4.18-rc1
v4.18-rc2
v4.18-rc3
v4.18-rc4
v4.18-rc5
v4.18-rc6
v4.18-rc7
v4.18-rc8
v4.19
v4.19-rc1
v4.19-rc2
v4.19-rc3
v4.19-rc4
v4.19-rc5
v4.19-rc6
v4.19-rc7
v4.19-rc8
v4.20
v4.20-rc1
v4.20-rc2
v4.20-rc3
v4.20-rc4
v4.20-rc5
v4.20-rc6
v4.20-rc7

v5.*

v5.0
v5.0-rc1
v5.0-rc2
v5.0-rc3
v5.0-rc4
v5.0-rc5
v5.0-rc6
v5.0-rc7
v5.0-rc8
v5.1
v5.1-rc1
v5.1-rc2
v5.1-rc3
v5.1-rc4
v5.1-rc5
v5.1-rc6
v5.1-rc7
v5.10
v5.10-rc1
v5.10-rc2
v5.10-rc3
v5.10-rc4
v5.10-rc5
v5.10-rc6
v5.10-rc7
v5.10.1
v5.10.10
v5.10.100
v5.10.101
v5.10.102
v5.10.103
v5.10.104
v5.10.105
v5.10.106
v5.10.107
v5.10.108
v5.10.109
v5.10.11
v5.10.110
v5.10.111
v5.10.112
v5.10.113
v5.10.114
v5.10.115
v5.10.116
v5.10.117
v5.10.118
v5.10.119
v5.10.12
v5.10.120
v5.10.121
v5.10.122
v5.10.123
v5.10.13
v5.10.14
v5.10.15
v5.10.16
v5.10.17
v5.10.18
v5.10.19
v5.10.2
v5.10.20
v5.10.21
v5.10.22
v5.10.23
v5.10.24
v5.10.25
v5.10.26
v5.10.27
v5.10.28
v5.10.29
v5.10.3
v5.10.30
v5.10.31
v5.10.32
v5.10.33
v5.10.34
v5.10.35
v5.10.36
v5.10.37
v5.10.38
v5.10.39
v5.10.4
v5.10.40
v5.10.41
v5.10.42
v5.10.43
v5.10.44
v5.10.45
v5.10.46
v5.10.47
v5.10.48
v5.10.49
v5.10.5
v5.10.50
v5.10.51
v5.10.52
v5.10.53
v5.10.54
v5.10.55
v5.10.56
v5.10.57
v5.10.58
v5.10.59
v5.10.6
v5.10.60
v5.10.61
v5.10.62
v5.10.63
v5.10.64
v5.10.65
v5.10.66
v5.10.67
v5.10.68
v5.10.69
v5.10.7
v5.10.70
v5.10.71
v5.10.72
v5.10.73
v5.10.74
v5.10.75
v5.10.76
v5.10.77
v5.10.78
v5.10.79
v5.10.8
v5.10.80
v5.10.81
v5.10.82
v5.10.83
v5.10.84
v5.10.85
v5.10.86
v5.10.87
v5.10.88
v5.10.89
v5.10.9
v5.10.90
v5.10.91
v5.10.92
v5.10.93
v5.10.94
v5.10.95
v5.10.96
v5.10.97
v5.10.98
v5.10.99
v5.11
v5.11-rc1
v5.11-rc2
v5.11-rc3
v5.11-rc4
v5.11-rc5
v5.11-rc6
v5.11-rc7
v5.12
v5.12-rc1
v5.12-rc1-dontuse
v5.12-rc2
v5.12-rc3
v5.12-rc4
v5.12-rc5
v5.12-rc6
v5.12-rc7
v5.12-rc8
v5.13
v5.13-rc1
v5.13-rc2
v5.13-rc3
v5.13-rc4
v5.13-rc5
v5.13-rc6
v5.13-rc7
v5.14
v5.14-rc1
v5.14-rc2
v5.14-rc3
v5.14-rc4
v5.14-rc5
v5.14-rc6
v5.14-rc7
v5.15
v5.15-rc1
v5.15-rc2
v5.15-rc3
v5.15-rc4
v5.15-rc5
v5.15-rc6
v5.15-rc7
v5.15.1
v5.15.10
v5.15.11
v5.15.12
v5.15.13
v5.15.14
v5.15.15
v5.15.16
v5.15.17
v5.15.18
v5.15.19
v5.15.2
v5.15.20
v5.15.21
v5.15.22
v5.15.23
v5.15.24
v5.15.25
v5.15.26
v5.15.27
v5.15.28
v5.15.29
v5.15.3
v5.15.30
v5.15.31
v5.15.32
v5.15.33
v5.15.34
v5.15.35
v5.15.36
v5.15.37
v5.15.38
v5.15.39
v5.15.4
v5.15.40
v5.15.41
v5.15.42
v5.15.43
v5.15.44
v5.15.45
v5.15.46
v5.15.47
v5.15.48
v5.15.5
v5.15.6
v5.15.7
v5.15.8
v5.15.9
v5.16
v5.16-rc1
v5.16-rc2
v5.16-rc3
v5.16-rc4
v5.16-rc5
v5.16-rc6
v5.16-rc7
v5.16-rc8
v5.17
v5.17-rc1
v5.17-rc2
v5.17-rc3
v5.17-rc4
v5.17-rc5
v5.17-rc6
v5.17-rc7
v5.17-rc8
v5.18
v5.18-rc1
v5.18-rc2
v5.18-rc3
v5.18-rc4
v5.18-rc5
v5.18-rc6
v5.18-rc7
v5.18.1
v5.18.2
v5.18.3
v5.18.4
v5.18.5
v5.19-rc1
v5.19-rc2
v5.2
v5.2-rc1
v5.2-rc2
v5.2-rc3
v5.2-rc4
v5.2-rc5
v5.2-rc6
v5.2-rc7
v5.3
v5.3-rc1
v5.3-rc2
v5.3-rc3
v5.3-rc4
v5.3-rc5
v5.3-rc6
v5.3-rc7
v5.3-rc8
v5.4
v5.4-rc1
v5.4-rc2
v5.4-rc3
v5.4-rc4
v5.4-rc5
v5.4-rc6
v5.4-rc7
v5.4-rc8
v5.5
v5.5-rc1
v5.5-rc2
v5.5-rc3
v5.5-rc4
v5.5-rc5
v5.5-rc6
v5.5-rc7
v5.6
v5.6-rc1
v5.6-rc2
v5.6-rc3
v5.6-rc4
v5.6-rc5
v5.6-rc6
v5.6-rc7
v5.7
v5.7-rc1
v5.7-rc2
v5.7-rc3
v5.7-rc4
v5.7-rc5
v5.7-rc6
v5.7-rc7
v5.8
v5.8-rc1
v5.8-rc2
v5.8-rc3
v5.8-rc4
v5.8-rc5
v5.8-rc6
v5.8-rc7
v5.9
v5.9-rc1
v5.9-rc2
v5.9-rc3
v5.9-rc4
v5.9-rc5
v5.9-rc6
v5.9-rc7
v5.9-rc8

Database specific

{
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b202a0bd2580ee5b0453772c46d464152fafff73",
            "signature_type": "Function",
            "target": {
                "function": "blk_mq_alloc_request_hctx",
                "file": "block/blk-mq.c"
            },
            "deprecated": false,
            "digest": {
                "length": 1093.0,
                "function_hash": "238601602800878957389631467227161787292"
            },
            "id": "CVE-2022-49720-0d5b5dad"
        },
        {
            "signature_version": "v1",
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@14dc7a18abbe4176f5626c13c333670da8e06aa1",
            "signature_type": "Line",
            "target": {
                "file": "block/blk-mq.c"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "215550995606810123331566987033104639702",
                    "46765092363884390795710142237505141050",
                    "337371794124370868918279009183147200080",
                    "97523806707997086942306438190604727380"
                ],
                "threshold": 0.9
            },
            "id": "CVE-2022-49720-31810d6b"
        },
        {
            "signature_version": "v1",
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b5e65ef044d627effdc2599040b6d204e003f955",
            "signature_type": "Function",
            "target": {
                "function": "blk_mq_alloc_request_hctx",
                "file": "block/blk-mq.c"
            },
            "deprecated": false,
            "digest": {
                "length": 1012.0,
                "function_hash": "23254047003897621175315211822804340825"
            },
            "id": "CVE-2022-49720-53548b5b"
        },
        {
            "signature_version": "v1",
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7fa28a7c3d74933a4fc22d341b60927952f31c19",
            "signature_type": "Function",
            "target": {
                "function": "blk_mq_alloc_request_hctx",
                "file": "block/blk-mq.c"
            },
            "deprecated": false,
            "digest": {
                "length": 1012.0,
                "function_hash": "23254047003897621175315211822804340825"
            },
            "id": "CVE-2022-49720-638b4430"
        },
        {
            "signature_version": "v1",
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b5e65ef044d627effdc2599040b6d204e003f955",
            "signature_type": "Line",
            "target": {
                "file": "block/blk-mq.c"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "239121458389819468876916437418681647729",
                    "46765092363884390795710142237505141050",
                    "337371794124370868918279009183147200080",
                    "97523806707997086942306438190604727380"
                ],
                "threshold": 0.9
            },
            "id": "CVE-2022-49720-7e148dae"
        },
        {
            "signature_version": "v1",
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b202a0bd2580ee5b0453772c46d464152fafff73",
            "signature_type": "Line",
            "target": {
                "file": "block/blk-mq.c"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "215550995606810123331566987033104639702",
                    "46765092363884390795710142237505141050",
                    "337371794124370868918279009183147200080",
                    "97523806707997086942306438190604727380"
                ],
                "threshold": 0.9
            },
            "id": "CVE-2022-49720-a4edd67b"
        },
        {
            "signature_version": "v1",
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@14dc7a18abbe4176f5626c13c333670da8e06aa1",
            "signature_type": "Function",
            "target": {
                "function": "blk_mq_alloc_request_hctx",
                "file": "block/blk-mq.c"
            },
            "deprecated": false,
            "digest": {
                "length": 1093.0,
                "function_hash": "238601602800878957389631467227161787292"
            },
            "id": "CVE-2022-49720-ca7a359f"
        },
        {
            "signature_version": "v1",
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7fa28a7c3d74933a4fc22d341b60927952f31c19",
            "signature_type": "Line",
            "target": {
                "file": "block/blk-mq.c"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "239121458389819468876916437418681647729",
                    "46765092363884390795710142237505141050",
                    "337371794124370868918279009183147200080",
                    "97523806707997086942306438190604727380"
                ],
                "threshold": 0.9
            },
            "id": "CVE-2022-49720-faee8bb2"
        }
    ]
}

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.16.0
Fixed
5.10.124
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.49
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.18.6