๐Ÿ” CVE Alert

CVE-2022-49327

MEDIUM 5.5

bcache: avoid journal no-space deadlock by reserving 1 journal bucket

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: bcache: avoid journal no-space deadlock by reserving 1 journal bucket The journal no-space deadlock was reported time to time. Such deadlock can happen in the following situation. When all journal buckets are fully filled by active jset with heavy write I/O load, the cache set registration (after a reboot) will load all active jsets and inserting them into the btree again (which is called journal replay). If a journaled bkey is inserted into a btree node and results btree node split, new journal request might be triggered. For example, the btree grows one more level after the node split, then the root node record in cache device super block will be upgrade by bch_journal_meta() from bch_btree_set_root(). But there is no space in journal buckets, the journal replay has to wait for new journal bucket to be reclaimed after at least one journal bucket replayed. This is one example that how the journal no-space deadlock happens. The solution to avoid the deadlock is to reserve 1 journal bucket in run time, and only permit the reserved journal bucket to be used during cache set registration procedure for things like journal replay. Then the journal space will never be fully filled, there is no chance for journal no-space deadlock to happen anymore. This patch adds a new member "bool do_reserve" in struct journal, it is inititalized to 0 (false) when struct journal is allocated, and set to 1 (true) by bch_journal_space_reserve() when all initialization done in run_cache_set(). In the run time when journal_reclaim() tries to allocate a new journal bucket, free_journal_buckets() is called to check whether there are enough free journal buckets to use. If there is only 1 free journal bucket and journal->do_reserve is 1 (true), the last bucket is reserved and free_journal_buckets() will return 0 to indicate no free journal bucket. Then journal_reclaim() will give up, and try next time to see whetheer there is free journal bucket to allocate. By this method, there is always 1 jouranl bucket reserved in run time. During the cache set registration, journal->do_reserve is 0 (false), so the reserved journal bucket can be used to avoid the no-space deadlock.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Feb 26, 2025
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new medium vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
cafe563591446cf80bfbc2fe3bc72a2e36cf1060 < 59afd4f287900c8187e968a4153ed35e6b48efce cafe563591446cf80bfbc2fe3bc72a2e36cf1060 < 5607652823ac65e2c6885e73bd46d5a4f9a20363 cafe563591446cf80bfbc2fe3bc72a2e36cf1060 < 6332ea3e35efa12dc08f0cbf5faea5e6e8eb0497 cafe563591446cf80bfbc2fe3bc72a2e36cf1060 < 1dda32aed6f62c163f38ff947ef5b3360e329159 cafe563591446cf80bfbc2fe3bc72a2e36cf1060 < 32feee36c30ea06e38ccb8ae6e5c44c6eec790a6
Linux / Linux
3.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/59afd4f287900c8187e968a4153ed35e6b48efce git.kernel.org: https://git.kernel.org/stable/c/5607652823ac65e2c6885e73bd46d5a4f9a20363 git.kernel.org: https://git.kernel.org/stable/c/6332ea3e35efa12dc08f0cbf5faea5e6e8eb0497 git.kernel.org: https://git.kernel.org/stable/c/1dda32aed6f62c163f38ff947ef5b3360e329159 git.kernel.org: https://git.kernel.org/stable/c/32feee36c30ea06e38ccb8ae6e5c44c6eec790a6