ceph: fix possible deadlock when holding Fwb to get inline_data
Published Feb 26, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.17%
Description
1, mount with wsync. 2, create a file with O_RDWR, and the request was sent to mds.0:
ceph_atomic_open()--> ceph_mdsc_do_request(openc) finish_open(file, dentry, ceph_open)--> ceph_open()--> ceph_init_file()--> ceph_init_file_info()--> ceph_uninline_data()--> { ... if (inline_version == 1 || /* initial version, no data */ inline_version == CEPH_INLINE_NONE) goto out_unlock; ... }
The inline_version will be 1, which is the initial version for the new create file. And here the ci->i_inline_version will keep with 1, it's buggy.
3, buffer write to the file immediately:
ceph_write_iter()--> ceph_get_caps(file, need=Fw, want=Fb, ...); generic_perform_write()--> a_ops->write_begin()--> ceph_write_begin()--> netfs_write_begin()--> netfs_begin_read()--> netfs_rreq_submit_slice()--> netfs_read_from_server()--> rreq->netfs_ops->issue_read()--> ceph_netfs_issue_read()--> { ... if (ci->i_inline_version != CEPH_INLINE_NONE && ceph_netfs_issue_op_inline(subreq)) return; ... } ceph_put_cap_refs(ci, Fwb);
The ceph_netfs_issue_op_inline() will send a getattr(Fsr) request to mds.1.
4, then the mds.1 will request the rd lock for CInode::filelock from the auth mds.0, the mds.0 will do the CInode::filelock state transation from excl --> sync, but it need to revoke the Fxwb caps back from the clients.
While the kernel client has aleady held the Fwb caps and waiting for the getattr(Fsr).
It's deadlock!
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.18StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.18
- Version 5.18.4StatusunaffectedConstraints<=5.18.*
- Version 5.19StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 2.6.34 · < 5.18.4
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-49296 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2347701 Issue Tracking
- https://git.kernel.org/stable/c/292b7a7275ce535a1abfa4dd0b2e586162aaae1e Patch
- https://git.kernel.org/stable/c/825978fd6a0defc3c29d8a38b6cea76a0938d21e Patch
- https://lore.kernel.org/linux-cve-announce/2025022625-CVE-2022-49296-f8f1@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49296
- https://www.cve.org/CVERecord?id=CVE-2022-49296
Change history (0)
No recorded changes yet.