Bug 2414504 (CVE-2025-40125)
| Summary: | CVE-2025-40125 kernel: blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
An error handling oversight was found in the Linux kernel's block multiqueue subsystem when managing hardware queue sysfs entries. A local user can trigger this issue when sysfs registration fails for hardware queues but later operations attempt to unregister them. Since the unregistration code doesn't verify whether sysfs creation succeeded, it tries to delete nonexistent kobject entries, causing kernfs warnings and potential system instability or denial of service.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2025-11-12 11:04:11 UTC
|