๐Ÿ” CVE Alert

CVE-2025-37906

UNKNOWN 0.0

ublk: fix race between io_uring_cmd_complete_in_task and ublk_cancel_cmd

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ublk: fix race between io_uring_cmd_complete_in_task and ublk_cancel_cmd ublk_cancel_cmd() calls io_uring_cmd_done() to complete uring_cmd, but we may have scheduled task work via io_uring_cmd_complete_in_task() for dispatching request, then kernel crash can be triggered. Fix it by not trying to canceling the command if ublk block request is started.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published May 20, 2025
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
216c8f5ef0f209a3797292c487bdaa6991ab4b92 < fb2eb9ddf556f93fef45201e1f9d2b8674bcc975 216c8f5ef0f209a3797292c487bdaa6991ab4b92 < f40139fde5278d81af3227444fd6e76a76b9506d
Linux / Linux
6.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/fb2eb9ddf556f93fef45201e1f9d2b8674bcc975 git.kernel.org: https://git.kernel.org/stable/c/f40139fde5278d81af3227444fd6e76a76b9506d