From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F3EA83A4F58 for ; Sun, 19 Jul 2026 15:40:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784475648; cv=none; b=RlmUqsw3xA8DysSnqEAEbYJPgFALJ9gWCr9vynbDPWkXHw8U+xFw7/0nRxHQ3k70bNu31/bwEkQiMETKeBCa7YEQCnps47f+XWfM4uCMwPJmbljDl6UyfbqV0jx1h3f1jyD//MUhpzoWDEeXS2V26/Qu1Ap4r4i8l8UW6ibXLYg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784475648; c=relaxed/simple; bh=UV1f2LwYzXwe7EJAGajJ3bGPriUthBqqNKNw4rqZqJw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=uPI1dcFQWqWFLLtMs7nCPbQPT/wbZp/V3mmaPU++iNZkafzGqA+YnVHVMXozdsW6fDOWcsoaN6Z7NdojObpvdmmQ+Xgxq8UR2o9seM0oIucbrjnv9j7zRF3mF81o04rR+cmlZcJZ+HM2J7pvUgog08Xd8d3ASaA2+c4/2pC2oak= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=NWs0uzbE; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="NWs0uzbE" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 099871F000E9; Sun, 19 Jul 2026 15:40:45 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1784475646; bh=llGWSeY8icZTVPU3lCYhf+X7/Kmj9Ko78fvyB6UIY30=; h=From:To:Cc:Subject:Date:Reply-To; b=NWs0uzbE6vZsHopRRSiYzRYPXi8p6uLyy7Wmc1foBZa3G5z2FV9qdNMxDn4GXfyyY ubqapVbWUaJSZ9LxNscdXsfrHZNfyYMgB5hd6nz8h63b1Edy4PB2P/IbMvAqxvpGZs haxGH+oXLdWYLIm4UNVDd27Y+fMb+mWkumoYKGEU= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-64017: blk-mq: pop cached request if it is usable Date: Sun, 19 Jul 2026 17:37:59 +0200 Message-ID: <2026071900-CVE-2026-64017-c8ee@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3161; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=07xRu4uXew69/9gh5eZEsloebfpknJrlIbnIjwNM5K0=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkx7yMkPbaITuzW1n5XkFa/3H6uVlMkg/mhaclsfndPH 3tvE8jbEcvCIMjEICumyPJlG8/R/RWHFL0MbU/DzGFlAhnCwMUpABN5YcGw4PLRGu4Ff8693Pym sWnS7jDhg6VvzjPMj9uSz/jmXUqPZezu+2mC6y5enZa3DQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: blk-mq: pop cached request if it is usable When submitting a bio to blk-mq, if the task should sleep after peeking a cached request, but before it pops it, the plug flushes and calls blk_mq_free_plug_rqs, freeing the cached_rqs. This creates a use-after-free bug. Fix this by popping the cached request before any possible blocking calls if it is suitable for use. Popping this request first holds a queue reference, so avoid any serialization races with queue freezes and can safely proceed with dispatching that request to the driver. This potentially increases a timing window from when a driver wants to freeze its queue to when requests stop being dispatched. That scenario is off the fast path though, and drivers need to appropriately handle requests during a freeze request anyway. The downside is the popped element needs to be individually freed when we performed a bio plug merge. The cached request would have had to be freed later anyway, but this patch does it inline with building the plug list instead of after flushing it. The Linux kernel CVE team has assigned CVE-2026-64017 to this issue. Affected and fixed versions =========================== Issue introduced in 6.7 with commit b0077e269f6c152e807fdac90b58caf012cdbaab and fixed in 7.0.11 with commit 388468f7e7d1eab092cf2a39fdfb502e52019ec6 Issue introduced in 6.7 with commit b0077e269f6c152e807fdac90b58caf012cdbaab and fixed in 7.1 with commit dc278e9bf2b9513a763353e6b9cc21e0f532954e Issue introduced in 6.1.72 with commit b5c8e0ff76d10f6bf70a7237678f27c20cf59bc9 Issue introduced in 6.5.13 with commit e9c309ded295b7f8849097d71ae231456ca79f78 Issue introduced in 6.6.3 with commit b80056bd75a16e4550873ecefe12bc8fd190b1cf Issue introduced in 6.1.75 with commit 33cf52b6e53a6aa55883aa7fb9ceffceff8488a6 Issue introduced in 6.6.14 with commit 8b6075046470c8756242dfe3fd058813636f69a3 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64017 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: block/blk-mq.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/388468f7e7d1eab092cf2a39fdfb502e52019ec6 https://git.kernel.org/stable/c/dc278e9bf2b9513a763353e6b9cc21e0f532954e