block: Fix handling of offline queues in blk_mq_alloc_request_hctx()
Published Feb 26, 2025
7.8
HIGHCVSS 3.1
EPSS 0.30%
Description
This patch prevents that test nvme/004 triggers the following:
UBSAN: array-index-out-of-bounds in block/blk-mq.h:135:9 index 512 is out of range for type 'long unsigned int [512]' Call Trace: show_stack+0x52/0x58 dump_stack_lvl+0x49/0x5e dump_stack+0x10/0x12 ubsan_epilogue+0x9/0x3b __ubsan_handle_out_of_bounds.cold+0x44/0x49 blk_mq_alloc_request_hctx+0x304/0x310 __nvme_submit_sync_cmd+0x70/0x200 [nvme_core] nvmf_connect_io_queue+0x23e/0x2a0 [nvme_fabrics] nvme_loop_connect_io_queues+0x8d/0xb0 [nvme_loop] nvme_loop_create_ctrl+0x58e/0x7d0 [nvme_loop] nvmf_create_ctrl+0x1d7/0x4d0 [nvme_fabrics] nvmf_dev_write+0xae/0x111 [nvme_fabrics] vfs_write+0x144/0x560 ksys_write+0xb7/0x140 __x64_sys_write+0x42/0x50 do_syscall_64+0x35/0x80 entry_SYSCALL_64_after_hwframe+0x44/0xae
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.16StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.16
- Version 5.10.124StatusunaffectedConstraints<=5.10.*
- Version 5.15.49StatusunaffectedConstraints<=5.15.*
- Version 5.18.6StatusunaffectedConstraints<=5.18.*
- Version 5.19StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 4.16 · < 5.10.214
- ≥ 5.11 · < 5.15.49
- ≥ 5.16 · < 5.18.6
- 5.19
- 5.19
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Oct 1, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2025-2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (4 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.30% (0.00297) | 20.31th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.29% (0.00286) | 20.09th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.02% (0.00016) | 1.91th | v4 (v2025.03.14) |
| Feb 27, 2025 | 0.04% (0.00045) | 18.25th | v3 (v2023.03.01) |
References (9)
- https://access.redhat.com/security/cve/CVE-2022-49720 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2347999 Issue Tracking
- https://git.kernel.org/stable/c/14dc7a18abbe4176f5626c13c333670da8e06aa1 Patch
- https://git.kernel.org/stable/c/7fa28a7c3d74933a4fc22d341b60927952f31c19 Patch
- https://git.kernel.org/stable/c/b202a0bd2580ee5b0453772c46d464152fafff73 Patch
- https://git.kernel.org/stable/c/b5e65ef044d627effdc2599040b6d204e003f955 Patch
- https://lore.kernel.org/linux-cve-announce/2025022632-CVE-2022-49720-b0a8@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49720
- https://www.cve.org/CVERecord?id=CVE-2022-49720
Change history (0)
No recorded changes yet.