We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2021-47412

block: don't call rq_qos_ops->done_bio if the bio isn't tracked



Description

In the Linux kernel, the following vulnerability has been resolved: block: don't call rq_qos_ops->done_bio if the bio isn't tracked rq_qos framework is only applied on request based driver, so: 1) rq_qos_done_bio() needn't to be called for bio based driver 2) rq_qos_done_bio() needn't to be called for bio which isn't tracked, such as bios ended from error handling code. Especially in bio_endio(): 1) request queue is referred via bio->bi_bdev->bd_disk->queue, which may be gone since request queue refcount may not be held in above two cases 2) q->rq_qos may be freed in blk_cleanup_queue() when calling into __rq_qos_done_bio() Fix the potential kernel panic by not calling rq_qos_ops->done_bio if the bio isn't tracked. This way is safe because both ioc_rqos_done_bio() and blkcg_iolatency_done_bio() are nop if the bio isn't tracked.

Reserved 2024-05-21 | Published 2024-05-21 | Updated 2025-05-04 | Assigner Linux

Product status

Default status
unaffected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 004b8f8a691205a93d9e80d98b786b2b97424d6e
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before a647a524a46736786c95cdb553a070322ca096e3
affected

Default status
affected

5.14.11
unaffected

5.15
unaffected

References

git.kernel.org/...c/004b8f8a691205a93d9e80d98b786b2b97424d6e

git.kernel.org/...c/a647a524a46736786c95cdb553a070322ca096e3

cve.org (CVE-2021-47412)

nvd.nist.gov (CVE-2021-47412)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2021-47412

Support options

Helpdesk Chat, Email, Knowledgebase