Description
In the Linux kernel, the following vulnerability has been resolved:

ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning

The hand-rolled bit-scanning loop in the NCQ completion path has an
infinite loop bug. When tag_mask has only high bits set (e.g.
0x80000000), the inner while loop left-shifts tag_mask until it
overflows to 0. At that point !(0 & 1) is always true and 0 <<= 1
stays 0, causing an infinite loop in hardirq context with a spinlock
held.

Replace the open-coded bit-scanning with __ffs() which correctly
finds the least significant set bit and is bounded by the width of
the argument.
Published: 2026-08-12
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel’s ATA driver for the DWC‑460ex SATA controller contains an infinite loop bug in the NCQ tag completion bit‑scanning routine. When the tag mask contains only high‑order bits (e.g., 0x80000000), the loop left‑shifts the mask until it overflows to zero. From that point, the condition never fails, keeping the kernel in a hard‑interrupt context while a spinlock is held. This causes the kernel to hang, resulting in a denial of service or potential crash.

Affected Systems

Linux kernel builds that include the ata driver for the DWC‑460ex SATA controller. No specific version range is listed in the CVE data; any kernel employing that driver is potentially affected.

Risk and Exploitability

The CVSS score is 5.5, but the EPSS score is below 1 % and the vulnerability is not yet listed in CISA’s KEV catalog, indicating a low exploitation probability. The attack vector is not explicitly documented; it is inferred that an attacker would need local access to trigger the specific SATA command pattern that sets the tag mask with high bits, which typically requires privileged or physical access to the host system. Once triggered, the vulnerable code will cause a kernel panic or stall, denying service to all users.

Generated by OpenCVE AI on August 13, 2026 at 13:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that incorporates the fix to the NCQ tag completion routine.
  • Rebuild or reinstall the kernel package if only source is available, ensuring the updated driver is in use.
  • If updating is not currently possible, consider using an alternative SATA controller or disabling the affected driver until a patch is applied.

Generated by OpenCVE AI on August 13, 2026 at 13:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4745-1 linux-6.12 security update
History

Wed, 19 Aug 2026 16:45:00 +0000


Thu, 13 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-835
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Wed, 12 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665
CWE-672

Wed, 12 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning The hand-rolled bit-scanning loop in the NCQ completion path has an infinite loop bug. When tag_mask has only high bits set (e.g. 0x80000000), the inner while loop left-shifts tag_mask until it overflows to 0. At that point !(0 & 1) is always true and 0 <<= 1 stays 0, causing an infinite loop in hardirq context with a spinlock held. Replace the open-coded bit-scanning with __ffs() which correctly finds the least significant set bit and is bounded by the width of the argument.
Title ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-19T16:35:43.051Z

Reserved: 2026-07-30T09:28:09.395Z

Link: CVE-2026-68449

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T01:17:07.810

Modified: 2026-08-19T17:20:50.690

Link: CVE-2026-68449

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-12T00:00:00Z

Links: CVE-2026-68449 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T13:45:03Z

Weaknesses
  • CWE-665

    Improper Initialization

  • CWE-672

    Operation on a Resource after Expiration or Release

  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')