« Volver al listado

CVE-2026-93057

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

scsi: ufs: core: Avoid possible memory reclaim deadlock in TX EQTR context

TX EQTR may run while devfreq gear scaling has quiesced the UFS tagset. In that context, functions ufshcd_tx_eqtr(), __ufshcd_tx_eqtr() and ufs_qcom_get_rx_fom() allocate memory with GFP_KERNEL. If direct reclaim is triggered, reclaim/writeback can depend on I/O to UFS device. Because the queue is quiesced, this can cause deadlock.

Use memalloc_noio_save/restore() in ufshcd_tx_eqtr() to cover all allocations in the TX EQTR call tree, including:

- params->eqtr_record in ufshcd_tx_eqtr()

Leer descripción completaMostrar menos

- eqtr_data in __ufshcd_tx_eqtr()

- params in ufs_qcom_get_rx_fom()

This is preferred over tagging individual call sites with GFP_NOIO, as it automatically covers any future allocations added anywhere in the call tree without requiring each caller to be aware of this constraint.

[mkp: fix label as suggested by Bart]

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93057",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "03e5d38e2f985d8d0b0a60508c0b422f664808e3",
              "lessThan": "a28a7d9b3bb116da788ae492c90465ec1a7fa6e8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "03e5d38e2f985d8d0b0a60508c0b422f664808e3",
              "lessThan": "760fc6f0e25a72832c2fcf37ecf5f1b770ec8374",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/ufs/core/ufs-txeq.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/ufs/core/ufs-txeq.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:59.323",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/760fc6f0e25a72832c2fcf37ecf5f1b770ec8374",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a28a7d9b3bb116da788ae492c90465ec1a7fa6e8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Avoid possible memory reclaim deadlock in TX EQTR context\n\nTX EQTR may run while devfreq gear scaling has quiesced the UFS\ntagset. In that context, functions ufshcd_tx_eqtr(), __ufshcd_tx_eqtr()\nand ufs_qcom_get_rx_fom() allocate memory with GFP_KERNEL. If direct\nreclaim is triggered, reclaim/writeback can depend on I/O to UFS\ndevice. Because the queue is quiesced, this can cause deadlock.\n\nUse memalloc_noio_save/restore() in ufshcd_tx_eqtr() to cover all\nallocations in the TX EQTR call tree, including:\n\n - params->eqtr_record in ufshcd_tx_eqtr()\n\n - eqtr_data in __ufshcd_tx_eqtr()\n\n - params in ufs_qcom_get_rx_fom()\n\nThis is preferred over tagging individual call sites with GFP_NOIO, as it\nautomatically covers any future allocations added anywhere in the call tree\nwithout requiring each caller to be aware of this constraint.\n\n[mkp: fix label as suggested by Bart]"
    }
  ],
  "lastModified": "2026-09-17T17:17:59.323",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}