« Volver al listado

CVE-2026-74392

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

dm: limit target bio polling to one shot

dm_poll_bio() is the ->poll_bio() callback for a stacked dm device. The caller only knows about the dm queue, so it may decide to do a spinning poll if it thinks a single queue is being polled. Passing those flags unchanged to the mapped clone lets blk_mq_poll() spin on a target queue from inside dm_poll_bio().

With io_uring IOPOLL on a dm-stripe target this can keep a task in

long enough to trigger an RCU CPU stall, before io_uring gets back to io_iopoll_check() and its need_resched() check.

Leer descripción completaMostrar menos

Keep dm's ->poll_bio() bounded by forcing one-shot polling for target bios. The caller can invoke dm_poll_bio() again if it wants to keep polling, and it also gets a chance to reap completions or reschedule between passes.

Detalles técnicos trazas, registros y código del informe original
  dm_poll_bio() -> bio_poll() -> blk_mq_poll()

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74392",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f22ecf9c14c12918e30f2179ef516e99eb8b2e49",
              "lessThan": "6c4ede3b771adbb3bf21ad4e8b8f2f6f6120c4f7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f22ecf9c14c12918e30f2179ef516e99eb8b2e49",
              "lessThan": "5aa0f9231cbacade065cedd8e9b5ebd067231171",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/md/dm.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/md/dm.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:41.163",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/5aa0f9231cbacade065cedd8e9b5ebd067231171",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6c4ede3b771adbb3bf21ad4e8b8f2f6f6120c4f7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm: limit target bio polling to one shot\n\ndm_poll_bio() is the ->poll_bio() callback for a stacked dm device.\nThe caller only knows about the dm queue, so it may decide to do a\nspinning poll if it thinks a single queue is being polled. Passing those\nflags unchanged to the mapped clone lets blk_mq_poll() spin on a target\nqueue from inside dm_poll_bio().\n\nWith io_uring IOPOLL on a dm-stripe target this can keep a task in\n\n  dm_poll_bio() -> bio_poll() -> blk_mq_poll()\n\nlong enough to trigger an RCU CPU stall, before io_uring gets back to\nio_iopoll_check() and its need_resched() check.\n\nKeep dm's ->poll_bio() bounded by forcing one-shot polling for target\nbios. The caller can invoke dm_poll_bio() again if it wants to keep\npolling, and it also gets a chance to reap completions or reschedule\nbetween passes."
    }
  ],
  "lastModified": "2026-08-17T06:19:34.260",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}