In the Linux kernel, the following vulnerability has been resolved:
block: don't call rq_qos_ops->done_bio if the bio isn't tracked
rq_qos framework is only applied on request based driver, so:
1) rq_qos_done_bio() needn't to be called for bio based driver
2) rq_qos_done_bio() needn't to be called for bio which isn't tracked,
such as bios ended from error handling code.
Especially in bio_endio():
1) request queue is referred via bio->bi_bdev->bd_disk->queue, which
may be gone since request queue refcount may not be held in above two
cases
2) q->rq_qos may be freed in blk_cleanup_queue() when calling into
__rq_qos_done_bio()
Fix the potential kernel panic by not calling rq_qos_ops->done_bio if
the bio isn't tracked. This way is safe because both ioc_rqos_done_bio()
and blkcg_iolatency_done_bio() are nop if the bio isn't tracked.
CVSS
No CVSS.
References
Configurations
No configuration.
History
28 Aug 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2024-05-21 15:15
Updated : 2025-08-28 15:15
NVD link : CVE-2021-47412
Mitre link : CVE-2021-47412
CVE.ORG link : CVE-2021-47412
JSON object : View
Products Affected
No product.
CWE
No CWE.