Executive brief
A vulnerability in the Linux kernel's block storage management component could allow a local user to crash the system. The issue occurs when resetting certain storage statistics, leading to a kernel panic. This results in a complete loss of system availability, potentially disrupting operations and requiring a manual reboot.
Technical details
A NULL pointer dereference vulnerability exists in the Linux kernel's blk-cgroup (Block Control Group) subsystem. The issue resides in the blkcg_reset_stats() function, where the blkg_iostat_set structure is cleared via memset but fails to re-initialize the 'blkg' and 'sync' fields. This lack of re-initialization leads to a NULL pointer access of the blkg pointer during subsequent operations, resulting in a kernel panic. An attacker with local access and the ability to trigger a statistics reset (typically via cgroup v1 interfaces) can exploit this to cause a Denial of Service (DoS). The vulnerability has been addressed by ensuring these fields are properly re-initialized after memory clearing.
Affected products
- Linux Linux Kernel 5.5 to 6.3.13, 6.4 to 6.4.4
Timeline
- 2023-06-06: other: Initial patch submitted to LKML
- 2025-09-18: disclosed: CVE published by kernel.org
- 2025-09-18: advisory: NVD entry created
References
- https://git.kernel.org/stable/c/0561aa6033dd181594116d705c41fc16e97161a2
- https://git.kernel.org/stable/c/3d2af77e31ade05ff7ccc3658c3635ec1bea0979
- https://git.kernel.org/stable/c/58c135513562698f222a58ba07dbdfcfb268aa0d
- https://git.kernel.org/stable/c/892faa76be894d324bf48b12a55c7af7be2bad83
- https://git.kernel.org/stable/c/abbce7f82613ea5eeefd0fc3c1c8e449b9cef2a2
- https://git.kernel.org/stable/c/b0d26283af612b9e0cc3188b0b88ad7fdea447e8