CVE-2022-49913: btrfs: fix inode list leak during backref walking at find_parent_nodes()
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix inode list leak during backref walking at findparentnodes()
During backref walking, at findparentnodes(), if we are dealing with a data extent and we get an error while resolving the indirect backrefs, at resolveindirectrefs(), or in the while loop that iterates over the refs in the direct refs rbtree, we end up leaking the inode lists attached to the direct refs we have in the direct refs rbtree that were not yet added to the refs ulist passed as argument to findparentnodes(). Since they were not yet added to the refs ulist and prelimrelease() does not free the lists, on error the caller can only free the lists attached to the refs that were added to the refs ulist, all the remaining refs get their inode lists never freed, therefore leaking their memory.
Fix this by having prelimrelease() always free any attached inode list to each ref found in the rbtree, and have findparentnodes() set the ref's inode list to NULL once it transfers ownership of the inode list to a ref added to the refs ulist passed to findparentnodes().
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-49913?
CVE-2022-49913 is classified with a medium severity due to its potential impact on data integrity within the Linux kernel.
How do I fix CVE-2022-49913?
To fix CVE-2022-49913, upgrading to the latest stable version of the Linux kernel that includes the patch is recommended.
What components are affected by CVE-2022-49913?
CVE-2022-49913 affects the btrfs file system within the Linux kernel during backref walking operations.
What kind of vulnerability is CVE-2022-49913?
CVE-2022-49913 is a data leak vulnerability that can occur during backref walking in the btrfs file system.
Who is impacted by CVE-2022-49913?
Users and administrators of Linux systems leveraging the btrfs filesystem could be impacted by CVE-2022-49913.