Impact
The vulnerability occurs in the Linux kernel's ublk subsystem, where an invalid user supplied address (sqe->addr) can be processed after the system has already marked the buffer as active. This results in the uring command being completed while the tag remains active, leading to a hang during teardown. The flaw arises from insufficient validation of the buffer before it is used and can cause a denial of service by freezing or stalling the kernel's block subsystem. The flaw is a classic example of improper input validation, which allows the kernel to enter an inconsistent state.
Affected Systems
The issue affects all Linux kernel builds that contain the ublk module when the UBLK_F_AUTO_BUF_REG flag is enabled. The exact affected versions are not listed in the data, but the patch commit is referenced in the provided kernel commit URLs. Therefore any system running a kernel that has not been updated to include the commit 653d22269a8b83b491f7f186a5d7872f14e6ddca will be vulnerable.
Risk and Exploitability
The CVSS score is not provided, but the EPSS score is listed as < 1%, indicating a low probability that this vulnerability will be actively exploited in the wild. It is not currently in CISA’s KEV catalog. The bug requires a privileged context to interact with the ublk subsystem, and the attacker would need to be able to issue uring commands to the kernel. Because the vulnerability can cause kernel hang rather than gain of code execution or privilege escalation, the risk is focused on availability. Even though exploitation is considered unlikely, the potential impact on availability justifies prompt patching or mitigation.
OpenCVE Enrichment