In the Linux kernel, the following vulnerability has been resolved:
block: Remove queue freezing from several sysfs store callbacks
Freezing the request queue from inside sysfs store callbacks may cause a deadlock in combination with the dm-multipath driver and the queue_if_no_path option. Additionally, freezing the request queue slows down system boot on systems where sysfs attributes are set synchronously.
Fix this by removing the blk_mq_freeze_queue() / blk_mq_unfreeze_queue() calls from the store callbacks that do not strictly need these callbacks. Add the __data_racy annotation to request_queue.rq_timeout to suppress KCSAN data race reports about the rq_timeout reads.
This patch may cause a small delay in applying the new settings.
For all the attributes affected by this patch, I/O will complete correctly whether the old or the new value of the attribute is used.
This patch affects the following sysfs attributes: * io_poll_delay * io_timeout * nomerges * read_ahead_kb * rq_affinity
Here is an example of a deadlock triggered by running test srp/002 if this patch is not applied:
task:multipathd Call Trace: <TASK> __schedule+0x8c1/0x1bf0 schedule+0xdd/0x270 schedule_preempt_disabled+0x1c/0x30 __mutex_lock+0xb89/0x1650 mutex_lock_nested+0x1f/0x30 dm_table_set_restrictions+0x823/0xdf0 __bind+0x166/0x590 dm_swap_table+0x2a7/0x490 do_resume+0x1b1/0x610 dev_suspend+0x55/0x1a0 ctl_ioctl+0x3a5/0x7e0 dm_ctl_ioctl+0x12/0x20 __x64_sys_ioctl+0x127/0x1a0 x64_sys_call+0xe2b/0x17d0 do_syscall_64+0x96/0x3a0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 </TASK> task:(udev-worker) Call Trace: <TASK> __schedule+0x8c1/0x1bf0 schedule+0xdd/0x270 blk_mq_freeze_queue_wait+0xf2/0x140 blk_mq_freeze_queue_nomemsave+0x23/0x30 queue_ra_store+0x14e/0x290 queue_attr_store+0x23e/0x2c0 sysfs_kf_write+0xde/0x140 kernfs_fop_write_iter+0x3b2/0x630 vfs_write+0x4fd/0x1390 ksys_write+0xfd/0x230 __x64_sys_write+0x76/0xc0 x64_sys_call+0x276/0x17d0 do_syscall_64+0x96/0x3a0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 </TASK>
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade kernel-rtUpgrade kernelNo solution exists | Jul 17, 2026 | Jan 14, 2026 |
| Ubuntu | — | Upgrade linux-image-azure-6.17Upgrade linux-image-aws-64kUpgrade linux-image-generic-64kUpgrade linux-image-6.17.0-1012-gcpUpgrade linux-image-aws-6.17Upgrade linux-image-6.17.0-1010-realtimeUpgrade linux-image-oem-24.04bUpgrade linux-image-generic-6.17Upgrade linux-image-gcp-64kUpgrade linux-image-azureUpgrade linux-image-virtual-6.17Upgrade linux-image-gcp-64k-6.17Upgrade linux-image-virtualUpgrade linux-image-6.17.0-1020-oemUpgrade linux-image-6.17.0-1012-awsUpgrade linux-image-genericUpgrade linux-image-6.17.0-1011-oracle-64kUpgrade linux-image-6.17.0-22-genericUpgrade linux-image-oem-24.04Upgrade linux-image-realtime-hwe-24.04Upgrade linux-image-virtual-hwe-24.04Upgrade linux-image-realtime-6.17Upgrade linux-image-oracle-64k-6.17Upgrade linux-image-oracle-64kUpgrade linux-image-6.17.0-1012-aws-64kUpgrade linux-image-oem-24.04dUpgrade linux-image-6.17.0-22-generic-64kUpgrade linux-image-6.17.0-1014-raspiUpgrade linux-image-awsUpgrade linux-image-realtimeUpgrade linux-image-oracle-6.17Upgrade linux-image-oracleUpgrade linux-image-generic-64k-6.17Upgrade linux-image-oem-24.04aUpgrade linux-image-aws-64k-6.17Upgrade linux-image-raspi-6.17Upgrade linux-image-6.17.0-1011-oracleUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.17.0-1012-gcp-64kUpgrade linux-image-oem-6.17Upgrade linux-image-6.17.0-1013-azureUpgrade linux-image-raspiUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-gcpUpgrade linux-image-oem-24.04cUpgrade linux-image-gcp-6.17 | Apr 17, 2026 | Jan 14, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub