CVE-2025-37906 Information
May 21, 2025
cve
Description
In the Linux kernel the following vulnerability has been resolved:
ublk: fix race between io_uring_cmd_complete_in_task and ublk_cancel_cmd
ublk_cancel_cmd() calls io_uring_cmd_done() to complete uring_cmd but we may have scheduled task work via io_uring_cmd_complete_in_task() for dispatching request then kernel crash can be triggered.
Fix it by not trying to canceling the command if ublk block request is started.
Reference
https://git.kernel.org/stable/c/f40139fde5278d81af3227444fd6e76a76b9506d https://git.kernel.org/stable/c/fb2eb9ddf556f93fef45201e1f9d2b8674bcc975
Share on: