Database/Kernel, userspace & hypervisor
Linux kernel iomap: memory corruption when recording I/O errors during writeback
Impact
When writeback hit an I/O error, iomap recorded the error against a mapping that could already have been torn down, producing a NULL dereference inside errseq_set()/__filemap_set_wb_err() and memory corruption in the writeback worker. The reporter reproduced it as a repeatable kernel oops on XFS over device-mapper under fsstress plus block errors. For an operator this is a stability and integrity problem on any node whose local or shared filesystem sees write errors - a flaky NVMe, a failing dm/LVM path, or a storage target that returns errors - and the crash lands in the writeback kthread, so the node is lost rather than the workload. There is no tenant-facing attack path in the record; it requires a filesystem that is already reporting I/O errors.
Who can reach it
Local. A user able to generate filesystem writeback traffic on a volume whose backing device returns I/O errors. Authentication to the node is required; the trigger is a storage fault, not attacker input alone.
What to do
Update to a stable kernel carrying the fix (five stable commits are linked; the record names no single fixed version) and reboot the node. On GPU nodes with local scratch NVMe this is a drain-and-reboot per node; schedule it with the next kernel maintenance rather than on its own. Until then, treat nodes logging I/O errors plus writeback oopses as hardware replacement candidates - the crash is a symptom of a device that is already failing.
References
Related entries
- Linux kernel (drivers/gpu/drm/vmwgfx): The dimensions of a DMA surface-copy box submitted in the command stream wereCVE-2022-50440 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/gpu/drm/nouveau): Importing a dma-buf whose backing buffer object fails to initialize leaves theCVE-2022-50454 · Linux kernel (drivers/gpu/drm/nouveau)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A memory or reference-count leak in the amdkfd (KFDCVE-2022-50528 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel (drivers/nvme/host): The PRP list mempool is sized in the wrong units, so a large I/O that needs two PRPCVE-2022-50756 · Linux kernel (drivers/nvme/host)High
- Linux kernel (netfilter): Integer overflow in nft_payload_copy_vlan - stack leak plus local privilege escalationCVE-2023-0179 · Linux kernel (netfilter)High
- Linux kernel (ALSA): Use-after-free in snd_ctl_elem_read - local privilege escalationCVE-2023-0266 · Linux kernel (ALSA)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.