Answer in brief
CVE-2022-49413 records a Unknown severity vulnerability in bfq: Update cgroup information before merging bio. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e21b7a0b988772e82e7147e1c659a5afe2ae003c <da9f3025d595956410ceaab2bea01980d7775948 || >=e21b7a0b988772e82e7147e1c659a5afe2ae003c <b06691af08b41dfd81052a3362514d9827b44bb1 || >=e21b7a0b988772e82e7147e1c659a5afe2ae003c <e8821f45612f2e6d9adb9c6ba0fb4184f57692aa || >=e21b7a0b988772e82e7147e1c659a5afe2ae003c <d9165200c5627a2cf4408eefabdf0058bdf95e1a || >=e21b7a0b988772e82e7147e1c659a5afe2ae003c <2a1077f17169a6059992a0bbdb330e0abad1e6d9 || >=e21b7a0b988772e82e7147e1c659a5afe2ae003c <ea591cd4eb270393810e7be01feb8fde6a34fbbe | da9f3025d595956410ceaab2bea01980d7775948, b06691af08b41dfd81052a3362514d9827b44bb1, e8821f45612f2e6d9adb9c6ba0fb4184f57692aa, d9165200c5627a2cf4408eefabdf0058bdf95e1a, 2a1077f17169a6059992a0bbdb330e0abad1e6d9, ea591cd4eb270393810e7be01feb8fde6a34fbbe |
| Linux/Linuxgeneric | 4.12 | Not reported |
Published upstream
Feb 26, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: bfq: Update cgroup information before merging bio When the process is migrated to a different cgroup (or in case of writeback just starts submitting bios associated with a different cgroup) bfq_merge_bio() can operate with stale cgroup information in bic. Thus the bio can be merged to a request from a different cgroup or it can result in merging of bfqqs for different cgroups or bfqqs of already dead cgroups and causing possible use-after-free issues. Fix the problem by updating cgroup information in bfq_merge_bio().
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2022-49413 records a Unknown severity vulnerability in bfq: Update cgroup information before merging bio. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e21b7a0b988772e82e7147e1c659a5afe2ae003c <da9f3025d595956410ceaab2bea01980d7775948 || >=e21b7a0b988772e82e7147e1c659a5afe2ae003c <b06691af08b41dfd81052a3362514d9827b44bb1 || >=e21b7a0b988772e82e7147e1c659a5afe2ae003c <e8821f45612f2e6d9adb9c6ba0fb4184f57692aa || >=e21b7a0b988772e82e7147e1c659a5afe2ae003c <d9165200c5627a2cf4408eefabdf0058bdf95e1a || >=e21b7a0b988772e82e7147e1c659a5afe2ae003c <2a1077f17169a6059992a0bbdb330e0abad1e6d9 || >=e21b7a0b988772e82e7147e1c659a5afe2ae003c <ea591cd4eb270393810e7be01feb8fde6a34fbbe | da9f3025d595956410ceaab2bea01980d7775948, b06691af08b41dfd81052a3362514d9827b44bb1, e8821f45612f2e6d9adb9c6ba0fb4184f57692aa, d9165200c5627a2cf4408eefabdf0058bdf95e1a, 2a1077f17169a6059992a0bbdb330e0abad1e6d9, ea591cd4eb270393810e7be01feb8fde6a34fbbe |
| Linux/Linuxgeneric | 4.12 | Not reported |
Published upstream
Feb 26, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: bfq: Update cgroup information before merging bio When the process is migrated to a different cgroup (or in case of writeback just starts submitting bios associated with a different cgroup) bfq_merge_bio() can operate with stale cgroup information in bic. Thus the bio can be merged to a request from a different cgroup or it can result in merging of bfqqs for different cgroups or bfqqs of already dead cgroups and causing possible use-after-free issues. Fix the problem by updating cgroup information in bfq_merge_bio().
Quoted source text, attributed separately from HOL analysis.