Description
In the Linux kernel, the following vulnerability has been resolved:

ublk: validate auto buf reg before taking uring_cmd

With UBLK_F_AUTO_BUF_REG, invalid sqe->addr can fail after
ublk_fill_io_cmd() has set UBLK_IO_FLAG_ACTIVE. The uring_cmd is
completed while the tag stays active, which can hang teardown.

Split validation from buffer apply so the check has no side effects,
then take the uring_cmd and store the already-validated buffer. Apply
the same order in FETCH so io->buf is not written before __ublk_fetch()
state checks.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Kernel Hang)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability occurs in the Linux kernel's ublk subsystem, where an invalid user supplied address (sqe->addr) can be processed after the system has already marked the buffer as active. This results in the uring command being completed while the tag remains active, leading to a hang during teardown. The flaw arises from insufficient validation of the buffer before it is used and can cause a denial of service by freezing or stalling the kernel's block subsystem. The flaw is a classic example of improper input validation, which allows the kernel to enter an inconsistent state.

Affected Systems

The issue affects all Linux kernel builds that contain the ublk module when the UBLK_F_AUTO_BUF_REG flag is enabled. The exact affected versions are not listed in the data, but the patch commit is referenced in the provided kernel commit URLs. Therefore any system running a kernel that has not been updated to include the commit 653d22269a8b83b491f7f186a5d7872f14e6ddca will be vulnerable.

Risk and Exploitability

The CVSS score is not provided, but the EPSS score is listed as < 1%, indicating a low probability that this vulnerability will be actively exploited in the wild. It is not currently in CISA’s KEV catalog. The bug requires a privileged context to interact with the ublk subsystem, and the attacker would need to be able to issue uring commands to the kernel. Because the vulnerability can cause kernel hang rather than gain of code execution or privilege escalation, the risk is focused on availability. Even though exploitation is considered unlikely, the potential impact on availability justifies prompt patching or mitigation.

Generated by OpenCVE AI on September 19, 2026 at 15:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit that validates the buffer before passing it to uring_cmd; verify that the UBLK_F_AUTO_BUF_REG flag is handled correctly.
  • If an immediate update is not possible, disable or avoid using the UBLK_F_AUTO_BUF_REG flag on all ublk devices until the patch is applied, to prevent the buffer validation path from being triggered.
  • Monitor kernel release notes and security advisories to ensure the vulnerability is addressed in future kernel updates.

Generated by OpenCVE AI on September 19, 2026 at 15:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ublk: validate auto buf reg before taking uring_cmd With UBLK_F_AUTO_BUF_REG, invalid sqe->addr can fail after ublk_fill_io_cmd() has set UBLK_IO_FLAG_ACTIVE. The uring_cmd is completed while the tag stays active, which can hang teardown. Split validation from buffer apply so the check has no side effects, then take the uring_cmd and store the already-validated buffer. Apply the same order in FETCH so io->buf is not written before __ublk_fetch() state checks.
Title ublk: validate auto buf reg before taking uring_cmd
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:39.434Z

Reserved: 2026-09-11T19:38:34.802Z

Link: CVE-2026-90323

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:30.307

Modified: 2026-09-17T17:17:30.307

Link: CVE-2026-90323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:15:14Z

Weaknesses
  • CWE-20

    Improper Input Validation