« Volver al listado

CVE-2025-39999

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

blk-mq: fix blk_mq_tags double free while nr_requests grown

In the case user trigger tags grow by queue sysfs attribute nr_requests, hctx->sched_tags will be freed directly and replaced with a new allocated tags, see blk_mq_tag_update_depth().

The problem is that hctx->sched_tags is from elevator->et->tags, while et->tags is still the freed tags, hence later elevator exit will try to free the tags again, causing kernel panic.

Fix this problem by replacing et->tags with new allocated tags as well.

Noted there are still some long term problems that will require some refactor to be fixed thoroughly[1].

Leer descripción completaMostrar menos

[1] https://lore.kernel.org/all/20250815080216.410665-1-yukuai1@huaweicloud.com/

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-39999",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "58567d8e95c096ad234963df90a2ca518901f4b6",
              "lessThan": "8faee580d63bc2a54a59dcdb7f9ce4de29384fec",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f5a6604f7a4405450e4a1f54e5430f47290c500f",
              "lessThan": "392b1d64911f4de8887fe8b68299fa8bd6e5b923",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f5a6604f7a4405450e4a1f54e5430f47290c500f",
              "lessThan": "ba28afbd9eff2a6370f23ef4e6a036ab0cfda409",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.16.4",
              "lessThan": "6.16.11",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "block/blk-mq-tag.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.16.11",
              "versionType": "semver",
              "lessThanOrEqual": "6.16.*"
            },
            {
              "status": "unaffected",
              "version": "6.17.1",
              "versionType": "semver",
              "lessThanOrEqual": "6.17.*"
            },
            {
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "block/blk-mq-tag.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-10-15T08:15:38.210",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/392b1d64911f4de8887fe8b68299fa8bd6e5b923",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8faee580d63bc2a54a59dcdb7f9ce4de29384fec",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ba28afbd9eff2a6370f23ef4e6a036ab0cfda409",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: fix blk_mq_tags double free while nr_requests grown\n\nIn the case user trigger tags grow by queue sysfs attribute nr_requests,\nhctx->sched_tags will be freed directly and replaced with a new\nallocated tags, see blk_mq_tag_update_depth().\n\nThe problem is that hctx->sched_tags is from elevator->et->tags, while\net->tags is still the freed tags, hence later elevator exit will try to\nfree the tags again, causing kernel panic.\n\nFix this problem by replacing et->tags with new allocated tags as well.\n\nNoted there are still some long term problems that will require some\nrefactor to be fixed thoroughly[1].\n\n[1] https://lore.kernel.org/all/20250815080216.410665-1-yukuai1@huaweicloud.com/"
    }
  ],
  "lastModified": "2026-06-17T09:18:59.240",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}