{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2022-49898","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-05-01T14:05:17.244Z","datePublished":"2025-05-01T14:10:44.873Z","dateUpdated":"2026-08-05T08:56:36.301Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T08:56:36.301Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix tree mod log mishandling of reallocated nodes\n\nWe have been seeing the following panic in production\n\n  kernel BUG at fs/btrfs/tree-mod-log.c:677!\n  invalid opcode: 0000 [#1] SMP\n  RIP: 0010:tree_mod_log_rewind+0x1b4/0x200\n  RSP: 0000:ffffc9002c02f890 EFLAGS: 00010293\n  RAX: 0000000000000003 RBX: ffff8882b448c700 RCX: 0000000000000000\n  RDX: 0000000000008000 RSI: 00000000000000a7 RDI: ffff88877d831c00\n  RBP: 0000000000000002 R08: 000000000000009f R09: 0000000000000000\n  R10: 0000000000000000 R11: 0000000000100c40 R12: 0000000000000001\n  R13: ffff8886c26d6a00 R14: ffff88829f5424f8 R15: ffff88877d831a00\n  FS:  00007fee1d80c780(0000) GS:ffff8890400c0000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00007fee1963a020 CR3: 0000000434f33002 CR4: 00000000007706e0\n  DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n  DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n  PKRU: 55555554\n  Call Trace:\n   btrfs_get_old_root+0x12b/0x420\n   btrfs_search_old_slot+0x64/0x2f0\n   ? tree_mod_log_oldest_root+0x3d/0xf0\n   resolve_indirect_ref+0xfd/0x660\n   ? ulist_alloc+0x31/0x60\n   ? kmem_cache_alloc_trace+0x114/0x2c0\n   find_parent_nodes+0x97a/0x17e0\n   ? ulist_alloc+0x30/0x60\n   btrfs_find_all_roots_safe+0x97/0x150\n   iterate_extent_inodes+0x154/0x370\n   ? btrfs_search_path_in_tree+0x240/0x240\n   iterate_inodes_from_logical+0x98/0xd0\n   ? btrfs_search_path_in_tree+0x240/0x240\n   btrfs_ioctl_logical_to_ino+0xd9/0x180\n   btrfs_ioctl+0xe2/0x2ec0\n   ? __mod_memcg_lruvec_state+0x3d/0x280\n   ? do_sys_openat2+0x6d/0x140\n   ? kretprobe_dispatcher+0x47/0x70\n   ? kretprobe_rethook_handler+0x38/0x50\n   ? rethook_trampoline_handler+0x82/0x140\n   ? arch_rethook_trampoline_callback+0x3b/0x50\n   ? kmem_cache_free+0xfb/0x270\n   ? do_sys_openat2+0xd5/0x140\n   __x64_sys_ioctl+0x71/0xb0\n   do_syscall_64+0x2d/0x40\n\nWhich is this code in tree_mod_log_rewind()\n\n\tswitch (tm->op) {\n        case BTRFS_MOD_LOG_KEY_REMOVE_WHILE_FREEING:\n\t\tBUG_ON(tm->slot < n);\n\nThis occurs because we replay the nodes in order that they happened, and\nwhen we do a REPLACE we will log a REMOVE_WHILE_FREEING for every slot,\nstarting at 0.  'n' here is the number of items in this block, which in\nthis case was 1, but we had 2 REMOVE_WHILE_FREEING operations.\n\nThe actual root cause of this was that we were replaying operations for\na block that shouldn't have been replayed.  Consider the following\nsequence of events\n\n1. We have an already modified root, and we do a btrfs_get_tree_mod_seq().\n2. We begin removing items from this root, triggering KEY_REPLACE for\n   it's child slots.\n3. We remove one of the 2 children this root node points to, thus triggering\n   the root node promotion of the remaining child, and freeing this node.\n4. We modify a new root, and re-allocate the above node to the root node of\n   this other root.\n\nThe tree mod log looks something like this\n\n\tlogical 0\top KEY_REPLACE (slot 1)\t\t\tseq 2\n\tlogical 0\top KEY_REMOVE (slot 1)\t\t\tseq 3\n\tlogical 0\top KEY_REMOVE_WHILE_FREEING (slot 0)\tseq 4\n\tlogical 4096\top LOG_ROOT_REPLACE (old logical 0)\tseq 5\n\tlogical 8192\top KEY_REMOVE_WHILE_FREEING (slot 1)\tseq 6\n\tlogical 8192\top KEY_REMOVE_WHILE_FREEING (slot 0)\tseq 7\n\tlogical 0\top LOG_ROOT_REPLACE (old logical 8192)\tseq 8\n\n>From here the bug is triggered by the following steps\n\n1.  Call btrfs_get_old_root() on the new_root.\n2.  We call tree_mod_log_oldest_root(btrfs_root_node(new_root)), which is\n    currently logical 0.\n3.  tree_mod_log_oldest_root() calls tree_mod_log_search_oldest(), which\n    gives us the KEY_REPLACE seq 2, and since that's not a\n    LOG_ROOT_REPLACE we incorrectly believe that we don't have an old\n    root, because we expect that the most recent change should be a\n    LOG_ROOT_REPLACE.\n4.  Back in tree_mod_log_oldest_root() we don't have a LOG_ROOT_REPLACE,\n    so we don't set old_root, we simply use our e\n---truncated---"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Reached through local VFS/ioctl paths on a mounted btrfs filesystem—primarily FS_IOC_FIEMAP via btrfs_is_data_extent_shared → find_parent_nodes → btrfs_search_old_slot → tree_mod_log_rewind, and CAP_SYS_ADMIN LOGICAL_INO. No in-kernel network protocol handler (ksmbd/nfsd) directly executes this rewind logic on remote peer input.\nAC:L - An unprivileged attacker can keep a transaction open with concurrent writes while looping fiemap (joining that transaction and holding a tree-mod seq), and drive tree balancing/freeing so freed nodes are reused as roots of other trees—the same sequence seen in production. Attacker-controlled concurrency and retries make success not dependent on conditions outside their influence.\nPR:L - fiemap requires only an open readable regular file on btrfs (e.g. under /home or /tmp); ioctl_fiemap/extent_fiemap perform no capability check before btrfs_is_data_extent_shared takes a tree-mod seq and enters the vulnerable rewind. LOGICAL_INO needs CAP_SYS_ADMIN, but the worst reachable case is unprivileged fiemap.\nUI:N - On an already-mounted btrfs volume the attacker creates/opens their own file, issues fiemap, and runs concurrent metadata-heavy writes themselves; no separate victim action such as mounting a crafted image is required.\nS:U - Impact is confined to the host kernel and the affected btrfs instance within one security authority; there is no VM escape, IOMMU bypass, or other cross-boundary effect.\nC:H - Replaying mod-log ops from a prior incarnation of a reallocated node reconstructs wrong child block pointers; search_old_slot then reads those bytenrs as nodes—including blocks since reused for attacker-controlled data—yielding arbitrary metadata/disk reads. With CONFIG_BUG=n the BUG_ON guard is compiled out so rewind continues into that confused walk (and oopses also dump register/stack state).\nI:H - The same incorrect rewind (and CONFIG_BUG=n continuation past BUG_ON(tm->slot < n), including KEY_ADD nritems underflow) poisons the reconstructed node state used for further walks, so attacker-influenced block content interpreted as key_ptrs directs subsequent tree operations—consistent with treating this class of metadata confusion as high integrity impact when the assertion is not a hard stop.\nA:H - The production failure is kernel BUG at tree_mod_log_rewind (invalid opcode), i.e. oops/panic; even without a full panic, crashing while holding tree-mod and path locks can wedge btrfs transactions and deny service for the filesystem/system."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/btrfs/extent-tree.c"],"versions":[{"version":"bd989ba359f2acb8bc5f5490e19010fc0a6f8356","lessThan":"007058eb8292efc4c88f921752194b83269da085","status":"affected","versionType":"git"},{"version":"bd989ba359f2acb8bc5f5490e19010fc0a6f8356","lessThan":"52b2b65c9eb56fd829dda323786db828627ff7e6","status":"affected","versionType":"git"},{"version":"bd989ba359f2acb8bc5f5490e19010fc0a6f8356","lessThan":"968b71583130b6104c9f33ba60446d598e327a8b","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/btrfs/extent-tree.c"],"versions":[{"version":"3.5","status":"affected"},{"version":"0","lessThan":"3.5","status":"unaffected","versionType":"semver"},{"version":"5.15.78","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.0.8","lessThanOrEqual":"6.0.*","status":"unaffected","versionType":"semver"},{"version":"6.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"5.15.78"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"6.0.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5","versionEndExcluding":"6.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/007058eb8292efc4c88f921752194b83269da085"},{"url":"https://git.kernel.org/stable/c/52b2b65c9eb56fd829dda323786db828627ff7e6"},{"url":"https://git.kernel.org/stable/c/968b71583130b6104c9f33ba60446d598e327a8b"}],"title":"btrfs: fix tree mod log mishandling of reallocated nodes","x_generator":{"engine":"bippy-1.2.0"}}}}