* CVE-2026-64017: blk-mq: pop cached request if it is usable
@ 2026-07-19 15:37 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-07-19 15:37 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
blk-mq: pop cached request if it is usable
When submitting a bio to blk-mq, if the task should sleep after peeking
a cached request, but before it pops it, the plug flushes and calls
blk_mq_free_plug_rqs, freeing the cached_rqs. This creates a
use-after-free bug. Fix this by popping the cached request before any
possible blocking calls if it is suitable for use.
Popping this request first holds a queue reference, so avoid any
serialization races with queue freezes and can safely proceed with
dispatching that request to the driver. This potentially increases a
timing window from when a driver wants to freeze its queue to when
requests stop being dispatched. That scenario is off the fast path
though, and drivers need to appropriately handle requests during a
freeze request anyway.
The downside is the popped element needs to be individually freed when
we performed a bio plug merge. The cached request would have had to be
freed later anyway, but this patch does it inline with building the plug
list instead of after flushing it.
The Linux kernel CVE team has assigned CVE-2026-64017 to this issue.
Affected and fixed versions
===========================
Issue introduced in 6.7 with commit b0077e269f6c152e807fdac90b58caf012cdbaab and fixed in 7.0.11 with commit 388468f7e7d1eab092cf2a39fdfb502e52019ec6
Issue introduced in 6.7 with commit b0077e269f6c152e807fdac90b58caf012cdbaab and fixed in 7.1 with commit dc278e9bf2b9513a763353e6b9cc21e0f532954e
Issue introduced in 6.1.72 with commit b5c8e0ff76d10f6bf70a7237678f27c20cf59bc9
Issue introduced in 6.5.13 with commit e9c309ded295b7f8849097d71ae231456ca79f78
Issue introduced in 6.6.3 with commit b80056bd75a16e4550873ecefe12bc8fd190b1cf
Issue introduced in 6.1.75 with commit 33cf52b6e53a6aa55883aa7fb9ceffceff8488a6
Issue introduced in 6.6.14 with commit 8b6075046470c8756242dfe3fd058813636f69a3
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-64017
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
block/blk-mq.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/388468f7e7d1eab092cf2a39fdfb502e52019ec6
https://git.kernel.org/stable/c/dc278e9bf2b9513a763353e6b9cc21e0f532954e
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-07-19 15:40 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-19 15:37 CVE-2026-64017: blk-mq: pop cached request if it is usable Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.