Description
In the Linux kernel, the following vulnerability has been resolved:

dm: limit target bio polling to one shot

dm_poll_bio() is the ->poll_bio() callback for a stacked dm device.
The caller only knows about the dm queue, so it may decide to do a
spinning poll if it thinks a single queue is being polled. Passing those
flags unchanged to the mapped clone lets blk_mq_poll() spin on a target
queue from inside dm_poll_bio().

With io_uring IOPOLL on a dm-stripe target this can keep a task in

dm_poll_bio() -> bio_poll() -> blk_mq_poll()

long enough to trigger an RCU CPU stall, before io_uring gets back to
io_iopoll_check() and its need_resched() check.

Keep dm's ->poll_bio() bounded by forcing one-shot polling for target
bios. The caller can invoke dm_poll_bio() again if it wants to keep
polling, and it also gets a chance to reap completions or reschedule
between passes.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Linux kernel allows a caller of dm_poll_bio() to request multiple cycles of polling on a target block device, causing the kernel’s blk_mq_poll() routine to spin within dm_poll_bio(). This excessive spinning can stall the RCU subsystem, preventing it from progressing and effectively freezing kernel threads that rely on RCU. The result is a denial‑of‑service condition where I/O operations and potentially all system activity become unresponsive until the RCU stall clears or the system is rebooted. The weakness is rooted in improper handling of poll flags and unbounded polling loops, corresponding to uncontrolled resource consumption.

Affected Systems

The defect is present in all Linux kernel releases that implement dm_poll_bio() without the one‑shot polling guard; exact version ranges are not specified in the data. Any machine running a affected kernel and using dm‑based devices (such as dm‑stripe) with io_uring IOPOLL enabled is potentially exposed.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity, and the EPSS score of <1% suggests a very low, but non‑zero, likelihood of exploitation. However, since the flaw exploits normal io_uring usage patterns and requires only that a task perform I/O on a dm‑stripe device, the attack vector is inferred to be local or remote code that can enqueue io_uring IOPOLL operations. The failure mode is a RCU CPU stall that can sever system responsiveness. The vulnerability is not currently listed in the CISA KEV catalog. Until a patch is released, the best assessment is that the risk is significant, but the exploitation probability remains low.

Generated by OpenCVE AI on August 22, 2026 at 01:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a kernel update that enforces one‑shot polling for dm target bios; consult the vendor’s release notes for a fix matching this CVE.
  • Temporarily disable I/Ouring IOPOLL on dm‑based targets, such as by setting io_uring_poller=none or bypassing the IOPOLL flag, until a kernel patch is available.
  • If disabling IOPOLL is not feasible, reduce the dm‑stripe stripe count or adjust I/O scheduler to mitigate RCU pressure until the vendor releases a fix.

Generated by OpenCVE AI on August 22, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1050
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 15 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Sat, 15 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm: limit target bio polling to one shot dm_poll_bio() is the ->poll_bio() callback for a stacked dm device. The caller only knows about the dm queue, so it may decide to do a spinning poll if it thinks a single queue is being polled. Passing those flags unchanged to the mapped clone lets blk_mq_poll() spin on a target queue from inside dm_poll_bio(). With io_uring IOPOLL on a dm-stripe target this can keep a task in dm_poll_bio() -> bio_poll() -> blk_mq_poll() long enough to trigger an RCU CPU stall, before io_uring gets back to io_iopoll_check() and its need_resched() check. Keep dm's ->poll_bio() bounded by forcing one-shot polling for target bios. The caller can invoke dm_poll_bio() again if it wants to keep polling, and it also gets a chance to reap completions or reschedule between passes.
Title dm: limit target bio polling to one shot
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:18:31.175Z

Reserved: 2026-08-15T05:44:03.891Z

Link: CVE-2026-74392

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:41.163

Modified: 2026-08-17T06:19:34.260

Link: CVE-2026-74392

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74392 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T02:00:17Z

Weaknesses
  • CWE-1050

    Excessive Platform Resource Consumption within a Loop