Executive brief
A vulnerability in the Linux kernel's block layer could allow a local user to cause a system crash. The issue occurs when the system manages how data is written to storage devices, specifically during changes to the I/O scheduler. An exploit could lead to a denial-of-service condition, impacting the availability of the affected server or workstation.
Technical details
A NULL pointer dereference vulnerability exists in the Linux kernel's block multi-queue (blk-mq) subsystem, specifically within the blk_mq_elv_switch_none function. The root cause is a race condition where the q->elevator pointer can become NULL after the sysfs_lock is acquired but before it is accessed, due to a concurrent elevator switch operation. A local attacker with sufficient privileges to trigger I/O scheduler changes could exploit this to cause a kernel panic (Denial of Service). The fix involves moving the NULL check for q->elevator inside the protection of the sysfs_lock mutex. Patches have been released for various stable kernel branches, including 6.4.7.
Affected products
- Linux Linux Kernel up to (excluding) 6.4.7
Timeline
- 2023-06-16: patched: Initial patch submitted to kernel.org
- 2025-09-16: advisory: CVE published by NVD