In the Linux kernel, the following vulnerability has been resolved:
block: fix race between wbt_enable_default and IO submission
When wbt_enable_default() is moved out of queue freezing in elevator_change(), it can cause the wbt inflight counter to become negative (-1), leading to hung tasks in the writeback path. Tasks get stuck in wbt_wait() because the counter is in an inconsistent state.
The issue occurs because wbt_enable_default() could race with IO submission, allowing the counter to be decremented before proper initialization. This manifests as:
rq_wait[0]: inflight: -1 has_waiters: True
rwb_enabled() checks the state, which can be updated exactly between wbt_wait() (rq_qos_throttle()) and wbt_track()(rq_qos_track()), then the inflight counter will become negative.
And results in hung task warnings like: task:kworker/u24:39 state:D stack:0 pid:14767 Call Trace: rq_qos_wait+0xb4/0x150 wbt_wait+0xa9/0x100 __rq_qos_throttle+0x24/0x40 blk_mq_submit_bio+0x672/0x7b0 ...
Fix this by:
1. Splitting wbt_enable_default() into: - __wbt_enable_default(): Returns true if wbt_init() should be called - wbt_enable_default(): Wrapper for existing callers (no init) - wbt_init_enable_default(): New function that checks and inits WBT
2. Using wbt_init_enable_default() in blk_register_queue() to ensure proper initialization during queue registration
3. Move wbt_init() out of wbt_enable_default() which is only for enabling disabled wbt from bfq and iocost, and wbt_init() isn't needed. Then the original lock warning can be avoided.
4. Removing the ELEVATOR_FLAG_ENABLE_WBT_ON_EXIT flag and its handling code since it's no longer needed
This ensures WBT is properly initialized before any IO can be submitted, preventing the counter from going negative.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 13, 2026 |
| Ubuntu | — | Upgrade linux-image-6.17.0-1012-aws-64kUpgrade linux-image-6.17.0-1014-raspiUpgrade linux-image-oem-24.04dUpgrade linux-image-oem-24.04aUpgrade linux-image-gcpUpgrade linux-image-gcp-64kUpgrade linux-image-virtual-6.17Upgrade linux-image-oem-24.04cUpgrade linux-image-oracle-64kUpgrade linux-image-6.17.0-22-generic-64kUpgrade linux-image-oracle-6.17Upgrade linux-image-oem-6.17Upgrade linux-image-realtime-6.17Upgrade linux-image-6.17.0-1010-realtimeUpgrade linux-image-aws-64k-6.17Upgrade linux-image-raspi-6.17Upgrade linux-image-azureUpgrade linux-image-6.17.0-1012-gcpUpgrade linux-image-realtimeUpgrade linux-image-gcp-6.17Upgrade linux-image-generic-hwe-24.04Upgrade linux-image-oracleUpgrade linux-image-6.17.0-22-genericUpgrade linux-image-generic-64k-6.17Upgrade linux-image-virtual-hwe-24.04Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-awsUpgrade linux-image-raspiUpgrade linux-image-6.17.0-1011-oracleUpgrade linux-image-6.17.0-1011-oracle-64kUpgrade linux-image-6.17.0-1013-azureUpgrade linux-image-6.17.0-1012-awsUpgrade linux-image-azure-6.17Upgrade linux-image-oem-24.04Upgrade linux-image-oem-24.04bUpgrade linux-image-generic-6.17Upgrade linux-image-6.17.0-1012-gcp-64kUpgrade linux-image-genericUpgrade linux-image-aws-6.17Upgrade linux-image-realtime-hwe-24.04Upgrade linux-image-oracle-64k-6.17Upgrade linux-image-aws-64kUpgrade linux-image-generic-64kUpgrade linux-image-virtualUpgrade linux-image-gcp-64k-6.17Upgrade linux-image-6.17.0-1020-oem | Apr 17, 2026 | Jan 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub