Description
In the Linux kernel, the following vulnerability has been resolved:

blk-wbt: remove WARN_ON_ONCE from wbt_init_enable_default()

wbt_init_enable_default() uses WARN_ON_ONCE to check for failures from
wbt_alloc() and wbt_init(). However, both are expected failure paths:

- wbt_alloc() can return NULL under memory pressure (-ENOMEM)
- wbt_init() can fail with -EBUSY if wbt is already registered

syzbot triggers this by injecting memory allocation failures during MTD
partition creation via ioctl(BLKPG), causing a spurious warning.

wbt_init_enable_default() is a best-effort initialization called from
blk_register_queue() with a void return type. Failure simply means the
disk operates without writeback throttling, which is harmless.

Replace WARN_ON_ONCE with plain if-checks, consistent with how
wbt_set_lat() in the same file already handles these failures. Add a
pr_warn() for the wbt_init() failure to retain diagnostic information
without triggering a full stack trace.
Published: 2026-06-26
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

wbt_init_enable_default() in the Linux kernel uses the WARN_ON_ONCE macro to detect failures from wbt_alloc() and wbt_init(). Both functions can legitimately fail under normal conditions – wbt_alloc() can return NULL when memory is exhausted and wbt_init() can return –EBUSY if the write‑back throttling component is already registered. The macro emits a stack trace each time it fires, causing clean, expected error cases to generate noisy warning log messages. Syzbot discovered this by forcing memory allocation failures during MTD partition creation through ioctl(BLKPG). The warning does not affect disk operation; the system continues without write‑back throttling, so there is no security impact beyond log noise.

Affected Systems

The flaw exists in the core block subsystem of the Linux kernel, affecting every release that has not incorporated the upstream patch that replaces WARN_ON_ONCE with explicit error checks. All distributions that ship their own kernel build – Linux kernel – are potentially impacted until they apply the patch supplied by the kernel maintainers.

Risk and Exploitability

The vulnerability has a CVSS score of 5.5 and is not listed in CISA’s KEV catalog. Its EPSS score is < 1%, indicating a very low exploitation probability. The only observable effect is the generation of spurious warning messages, which cannot be used for privilege escalation, data exfiltration, or denial of service. Consequently the risk remains low; the issue is primarily noise that can mislead operators. Monitoring for unexpected BLKPG warnings and applying a patch are sufficient to eliminate the problem.

Generated by OpenCVE AI on August 13, 2026 at 13:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade your Linux kernel to a version that incorporates the upstream patch replacing WARN_ON_ONCE in wbt_init_enable_default().
  • If an official kernel upgrade is not feasible, fetch the upstream patch from the kernel commit history (e.g., commit c9b004ff) and apply it to your kernel source, then rebuild and reinstall the kernel.
  • As a temporary workaround, configure your system logs to filter or suppress WARN_ON_ONCE messages generated by blk_wbt, or de‑activate the BLKPG ioctl debugging feature until the patch can be applied.

Generated by OpenCVE AI on August 13, 2026 at 13:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8566-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8568-1 Linux kernel (OEM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8569-1 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-8593-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8603-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8618-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8663-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8664-1 Linux kernel (NVIDIA BaseOS) vulnerabilities
History

Mon, 29 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-209

Mon, 29 Jun 2026 12:15:00 +0000


Fri, 26 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-209

Fri, 26 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: blk-wbt: remove WARN_ON_ONCE from wbt_init_enable_default() wbt_init_enable_default() uses WARN_ON_ONCE to check for failures from wbt_alloc() and wbt_init(). However, both are expected failure paths: - wbt_alloc() can return NULL under memory pressure (-ENOMEM) - wbt_init() can fail with -EBUSY if wbt is already registered syzbot triggers this by injecting memory allocation failures during MTD partition creation via ioctl(BLKPG), causing a spurious warning. wbt_init_enable_default() is a best-effort initialization called from blk_register_queue() with a void return type. Failure simply means the disk operates without writeback throttling, which is harmless. Replace WARN_ON_ONCE with plain if-checks, consistent with how wbt_set_lat() in the same file already handles these failures. Add a pr_warn() for the wbt_init() failure to retain diagnostic information without triggering a full stack trace.
Title blk-wbt: remove WARN_ON_ONCE from wbt_init_enable_default()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-06-26T19:41:11.269Z

Reserved: 2026-06-09T07:44:35.398Z

Link: CVE-2026-53319

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-06-26T20:17:25.230

Modified: 2026-07-06T20:12:26.307

Link: CVE-2026-53319

cve-icon Redhat

Severity :

Publid Date: 2026-06-26T00:00:00Z

Links: CVE-2026-53319 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T13:15:04Z

Weaknesses
  • CWE-544

    Missing Standardized Error Handling Mechanism

  • CWE-617

    Reachable Assertion