CVE-2023-53531

EUVD-2025-32735
In the Linux kernel, the following vulnerability has been resolved:

null_blk: fix poll request timeout handling

When doing io_uring benchmark on /dev/nullb0, it's easy to crash the
kernel if poll requests timeout triggered, as reported by David. [1]

BUG: kernel NULL pointer dereference, address: 0000000000000008
Workqueue: kblockd blk_mq_timeout_work
RIP: 0010:null_timeout_rq+0x4e/0x91
Call Trace:
 ? null_timeout_rq+0x4e/0x91
 blk_mq_handle_expired+0x31/0x4b
 bt_iter+0x68/0x84
 ? bt_tags_iter+0x81/0x81
 __sbitmap_for_each_set.constprop.0+0xb0/0xf2
 ? __blk_mq_complete_request_remote+0xf/0xf
 bt_for_each+0x46/0x64
 ? __blk_mq_complete_request_remote+0xf/0xf
 ? percpu_ref_get_many+0xc/0x2a
 blk_mq_queue_tag_busy_iter+0x14d/0x18e
 blk_mq_timeout_work+0x95/0x127
 process_one_work+0x185/0x263
 worker_thread+0x1b5/0x227

This is indeed a race problem between null_timeout_rq() and null_poll().

null_poll()				null_timeout_rq()
  spin_lock(&nq->poll_lock)
  list_splice_init(&nq->poll_list, &list)
  spin_unlock(&nq->poll_lock)

  while (!list_empty(&list))
    req = list_first_entry()
    list_del_init()
    ...
    blk_mq_add_to_batch()
    // req->rq_next = NULL
					spin_lock(&nq->poll_lock)

					// rq->queuelist->next == NULL
					list_del_init(&rq->queuelist)

					spin_unlock(&nq->poll_lock)

Fix these problems by setting requests state to MQ_RQ_COMPLETE under
nq->poll_lock protection, in which null_timeout_rq() can safely detect
this race and early return.

Note this patch just fix the kernel panic when request timeout happen.

[1] https://lore.kernel.org/all/3893581.1691785261@warthog.procyon.org.uk/
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
5.16 ≤
𝑥
< 6.1.54
linuxlinux_kernel
6.2 ≤
𝑥
< 6.5.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.148-1
fixed
bookworm (security)
6.1.153-1
fixed
bullseye
5.10.223-1
not-affected
bullseye (security)
5.10.237-1
fixed
forky
6.16.8-1
fixed
sid
6.16.9-1
fixed
trixie
6.12.43-1
fixed
trixie (security)
6.12.48-1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
cluster-md-kmp-default
suse enterprise server 15 SP5
5.14.21-150500.55.124.1
fixed
dlm-kmp-default
suse enterprise server 15 SP5
5.14.21-150500.55.124.1
fixed
gfs2-kmp-default
suse enterprise server 15 SP5
5.14.21-150500.55.124.1
fixed
kernel-64kb
suse enterprise desktop 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.124.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.22.1
fixed
kernel-azure
suse enterprise sap 15 SP6
6.4.0-150600.8.52.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.20.18.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.8.52.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.20.18.1
fixed
kernel-default
suse enterprise desktop 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.124.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.22.1
fixed
kernel-default-base
suse enterprise desktop 15 SP6
6.4.0-150600.23.73.1.150600.12.32.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.22.1.150700.17.15.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.73.1.150600.12.32.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.22.1.150700.17.15.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.124.1.150500.6.59.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.73.1.150600.12.32.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.22.1.150700.17.15.1
fixed
kernel-docs
suse enterprise desktop 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.124.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.22.1
fixed
kernel-macros
suse enterprise desktop 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.124.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.22.1
fixed
kernel-obs-build
suse enterprise desktop 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.124.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.22.1
fixed
kernel-source
suse enterprise desktop 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.124.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.22.1
fixed
kernel-source-azure
suse enterprise sap 15 SP6
6.4.0-150600.8.52.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.20.18.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.8.52.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.20.18.1
fixed
kernel-syms
suse enterprise desktop 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.124.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.22.1
fixed
kernel-syms-azure
suse enterprise sap 15 SP6
6.4.0-150600.8.52.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.20.18.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.8.52.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.20.18.1
fixed
kernel-zfcpdump
suse enterprise desktop 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.22.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.124.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.73.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.22.1
fixed
ocfs2-kmp-default
suse enterprise server 15 SP5
5.14.21-150500.55.124.1
fixed
reiserfs-kmp-default
suse enterprise server 15 SP5
5.14.21-150500.55.124.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
bpftool
RHEL 9
0:7.4.0-503.11.1.el9_5
fixed
kernel
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-64k
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-64k-core
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-64k-debug
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-64k-debug-core
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-64k-debug-devel
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-64k-debug-devel-matched
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-64k-debug-modules
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-64k-debug-modules-core
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-64k-debug-modules-extra
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-64k-devel
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-64k-devel-matched
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-64k-modules
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-64k-modules-core
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-64k-modules-extra
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-abi-stablelists
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-core
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-debug
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-debug-core
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-debug-devel
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-debug-devel-matched
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-debug-modules
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-debug-modules-core
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-debug-modules-extra
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-debug-uki-virt
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-devel
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-devel-matched
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-doc
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-modules
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-modules-core
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-modules-extra
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-rt
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-rt-core
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-rt-debug
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-rt-debug-core
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-rt-debug-devel
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-rt-debug-kvm
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-rt-debug-modules
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-rt-debug-modules-core
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-rt-debug-modules-extra
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-rt-devel
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-rt-kvm
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-rt-modules
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-rt-modules-core
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-rt-modules-extra
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-tools
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-tools-libs
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-tools-libs-devel
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-uki-virt
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-uki-virt-addons
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-zfcpdump
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-zfcpdump-core
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-zfcpdump-devel
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-zfcpdump-devel-matched
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-zfcpdump-modules
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-zfcpdump-modules-core
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
kernel-zfcpdump-modules-extra
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
libperf
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
perf
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
python3-perf
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
rtla
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed
rv
RHEL 9
0:5.14.0-503.11.1.el9_5
fixed