CVE-2025-37759

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-37759
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37759.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-37759
Downstream
Published
2025-05-01T12:56:03.462Z
Modified
2025-11-16T16:18:58.115113Z
Summary
ublk: fix handling recovery & reissue in ublk_abort_queue()
Details

In the Linux kernel, the following vulnerability has been resolved:

ublk: fix handling recovery & reissue in ublkabortqueue()

Commit 8284066946e6 ("ublk: grab request reference when the request is handled by userspace") doesn't grab request reference in case of recovery reissue. Then the request can be requeued & re-dispatch & failed when canceling uring command.

If it is one zc request, the request can be freed before io_uring returns the zc buffer back, then cause kernel panic:

[ 126.773061] BUG: kernel NULL pointer dereference, address: 00000000000000c8 [ 126.773657] #PF: supervisor read access in kernel mode [ 126.774052] #PF: errorcode(0x0000) - not-present page [ 126.774455] PGD 0 P4D 0 [ 126.774698] Oops: Oops: 0000 [#1] SMP NOPTI [ 126.775034] CPU: 13 UID: 0 PID: 1612 Comm: kworker/u64:55 Not tainted 6.14.0blk+ #182 PREEMPT(full) [ 126.775676] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-1.fc39 04/01/2014 [ 126.776275] Workqueue: iouexit ioringexitwork [ 126.776651] RIP: 0010:ublkiorelease+0x14/0x130 [ublk_drv]

Fixes it by always grabbing request reference for aborting the request.

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8284066946e6d9cc979566ce698fe24e7ca0b31e
Fixed
caa5c8a2358604f38bf0a4afaa5eacda13763067
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8284066946e6d9cc979566ce698fe24e7ca0b31e
Fixed
5d34a30efac9c9c93e150130caa940c0df6053c1
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8284066946e6d9cc979566ce698fe24e7ca0b31e
Fixed
0a21d259ca4d6310fdfcc0284ebbc000e66cbf70
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8284066946e6d9cc979566ce698fe24e7ca0b31e
Fixed
6ee6bd5d4fce502a5b5a2ea805e9ff16e6aa890f

Affected versions

v6.*

v6.10
v6.10-rc1
v6.10-rc2
v6.10-rc3
v6.10-rc4
v6.10-rc5
v6.10-rc6
v6.10-rc7
v6.11
v6.11-rc1
v6.11-rc2
v6.11-rc3
v6.11-rc4
v6.11-rc5
v6.11-rc6
v6.11-rc7
v6.12
v6.12-rc1
v6.12-rc2
v6.12-rc3
v6.12-rc4
v6.12-rc5
v6.12-rc6
v6.12-rc7
v6.12.1
v6.12.10
v6.12.11
v6.12.12
v6.12.13
v6.12.14
v6.12.15
v6.12.16
v6.12.17
v6.12.18
v6.12.19
v6.12.2
v6.12.20
v6.12.21
v6.12.22
v6.12.23
v6.12.3
v6.12.4
v6.12.5
v6.12.6
v6.12.7
v6.12.8
v6.12.9
v6.13
v6.13-rc1
v6.13-rc2
v6.13-rc3
v6.13-rc4
v6.13-rc5
v6.13-rc6
v6.13-rc7
v6.13.1
v6.13.10
v6.13.11
v6.13.2
v6.13.3
v6.13.4
v6.13.5
v6.13.6
v6.13.7
v6.13.8
v6.13.9
v6.14
v6.14-rc1
v6.14-rc2
v6.14-rc3
v6.14-rc4
v6.14-rc5
v6.14-rc6
v6.14-rc7
v6.14.1
v6.14.2
v6.4
v6.4-rc3
v6.4-rc4
v6.4-rc5
v6.4-rc6
v6.4-rc7
v6.5
v6.5-rc1
v6.5-rc2
v6.5-rc3
v6.5-rc4
v6.5-rc5
v6.5-rc6
v6.5-rc7
v6.6
v6.6-rc1
v6.6-rc2
v6.6-rc3
v6.6-rc4
v6.6-rc5
v6.6-rc6
v6.6-rc7
v6.7
v6.7-rc1
v6.7-rc2
v6.7-rc3
v6.7-rc4
v6.7-rc5
v6.7-rc6
v6.7-rc7
v6.7-rc8
v6.8
v6.8-rc1
v6.8-rc2
v6.8-rc3
v6.8-rc4
v6.8-rc5
v6.8-rc6
v6.8-rc7
v6.9
v6.9-rc1
v6.9-rc2
v6.9-rc3
v6.9-rc4
v6.9-rc5
v6.9-rc6
v6.9-rc7

Database specific

vanir_signatures

[
    {
        "signature_type": "Function",
        "digest": {
            "length": 223.0,
            "function_hash": "160821956272693211153623844200201995035"
        },
        "target": {
            "function": "__ublk_fail_req",
            "file": "drivers/block/ublk_drv.c"
        },
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5d34a30efac9c9c93e150130caa940c0df6053c1",
        "id": "CVE-2025-37759-04551a86"
    },
    {
        "signature_type": "Function",
        "digest": {
            "length": 223.0,
            "function_hash": "160821956272693211153623844200201995035"
        },
        "target": {
            "function": "__ublk_fail_req",
            "file": "drivers/block/ublk_drv.c"
        },
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6ee6bd5d4fce502a5b5a2ea805e9ff16e6aa890f",
        "id": "CVE-2025-37759-0943a124"
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "203857313287078188394571307412298259976",
                "325774230413687021066481483029297930607",
                "98219852618587221591664812554719958657",
                "49747703654880132180164740739275402890",
                "319647745528073259836240228323724642668",
                "181020286076026678653339909661764888416",
                "329360886951977972335650290024852990574",
                "81091371620198031919813848094238274494",
                "24718083683237058463141190980257568123",
                "53363217018985887517949004582156830029"
            ]
        },
        "target": {
            "file": "drivers/block/ublk_drv.c"
        },
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5d34a30efac9c9c93e150130caa940c0df6053c1",
        "id": "CVE-2025-37759-168ade46"
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "203857313287078188394571307412298259976",
                "325774230413687021066481483029297930607",
                "98219852618587221591664812554719958657",
                "49747703654880132180164740739275402890",
                "319647745528073259836240228323724642668",
                "181020286076026678653339909661764888416",
                "329360886951977972335650290024852990574",
                "81091371620198031919813848094238274494",
                "24718083683237058463141190980257568123",
                "53363217018985887517949004582156830029"
            ]
        },
        "target": {
            "file": "drivers/block/ublk_drv.c"
        },
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0a21d259ca4d6310fdfcc0284ebbc000e66cbf70",
        "id": "CVE-2025-37759-184e999e"
    },
    {
        "signature_type": "Function",
        "digest": {
            "length": 223.0,
            "function_hash": "160821956272693211153623844200201995035"
        },
        "target": {
            "function": "__ublk_fail_req",
            "file": "drivers/block/ublk_drv.c"
        },
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0a21d259ca4d6310fdfcc0284ebbc000e66cbf70",
        "id": "CVE-2025-37759-4bfd16e3"
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "203857313287078188394571307412298259976",
                "325774230413687021066481483029297930607",
                "98219852618587221591664812554719958657",
                "49747703654880132180164740739275402890",
                "319647745528073259836240228323724642668",
                "181020286076026678653339909661764888416",
                "329360886951977972335650290024852990574",
                "81091371620198031919813848094238274494",
                "24718083683237058463141190980257568123",
                "53363217018985887517949004582156830029"
            ]
        },
        "target": {
            "file": "drivers/block/ublk_drv.c"
        },
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@caa5c8a2358604f38bf0a4afaa5eacda13763067",
        "id": "CVE-2025-37759-66159f65"
    },
    {
        "signature_type": "Function",
        "digest": {
            "length": 223.0,
            "function_hash": "160821956272693211153623844200201995035"
        },
        "target": {
            "function": "__ublk_fail_req",
            "file": "drivers/block/ublk_drv.c"
        },
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@caa5c8a2358604f38bf0a4afaa5eacda13763067",
        "id": "CVE-2025-37759-7ca1329f"
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "203857313287078188394571307412298259976",
                "325774230413687021066481483029297930607",
                "98219852618587221591664812554719958657",
                "49747703654880132180164740739275402890",
                "319647745528073259836240228323724642668",
                "181020286076026678653339909661764888416",
                "329360886951977972335650290024852990574",
                "81091371620198031919813848094238274494",
                "24718083683237058463141190980257568123",
                "53363217018985887517949004582156830029"
            ]
        },
        "target": {
            "file": "drivers/block/ublk_drv.c"
        },
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6ee6bd5d4fce502a5b5a2ea805e9ff16e6aa890f",
        "id": "CVE-2025-37759-d0af4e94"
    }
]

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.5.0
Fixed
6.12.24
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.12
Type
ECOSYSTEM
Events
Introduced
6.14.0
Fixed
6.14.3