Impact
During the removal of a ublk device, the kernel allocates a temporary xarray to unpin pages while holding the maple tree lock. If the atomic allocation fails, a range remains in the tree and the function returns false, causing an immediate retry of the same range. Because the allocation keeps failing, the teardown path stalls indefinitely, preventing forward progress and ultimately causing a denial of service. The weakness is an uncontrolled loop (CWE‑674) that also leads to a denial of service (CWE‑400).
Affected Systems
The bug exists in Linux kernels that include the ublk driver (CONFIG_BLK_DEV_UBLK=y) and any release prior to the commit that introduced the fix (4fd66a7f). The flaw is present in all distributions that support ublk devices, regardless of vendor, as long as the driver is compiled and loaded.
Risk and Exploitability
The vulnerability has a low EPSS score (<1%) and is not listed in the CISA KEV catalog, indicating that large‑scale exploitation has not been observed. The attack vector is local and requires the ability to register ublk devices and, optionally, to induce allocation failures through fault‑injection mechanisms such as failslab. While the impact is severe—potential kernel lockup or indefinite denial of service—the prevalence of the attack conditions is limited. Nonetheless, the flaw poses a high availability risk; applying the patch or otherwise disabling the affected code path is recommended to mitigate the risk.
OpenCVE Enrichment