blk-cgroup: properly pin the parent in blkcg_css_online
Published May 1, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.17%
Description
blkcg_css_online is supposed to pin the blkcg of the parent, but 397c9f46ee4d refactored things and along the way, changed it to pin the css instead. This results in extra pins, and we end up leaking blkcgs and cgroups.
Affected products
-
Affected
- ≥ , <
- ≥ , <
-
Affected
- 5.19
Unaffected
- ≥ 0, < 5.19
- ≥ 6.0.10, ≤ 6.0.*
- 6.1
- ≥ 5.19 · < 6.0.10
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A resource leak was identified in blkcg_css_online() where the current css was pinned instead of its parent, leading to extra references and memory not being freed. This issue can only be triggered by privileged users with CAP_SYS_ADMIN rights and does not allow for privilege escalation or data leakage. The leak may slowly exhaust kernel memory in systems making frequent use of cgroups and block I/O throttling.
No CWE recorded.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-49786 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2363368 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-12998 Advisory
- https://git.kernel.org/stable/c/d118247e404d6338f7b90636a3c6b95a387ed163 Patch
- https://git.kernel.org/stable/c/d7dbd43f4a828fa1d9a8614d5b0ac40aee6375fe Patch
- https://lore.kernel.org/linux-cve-announce/2025050121-CVE-2022-49786-bd75@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49786
- https://www.cve.org/CVERecord?id=CVE-2022-49786
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data