Executive brief
A vulnerability in the Linux kernel's disk encryption component (dm-crypt) can lead to system deadlocks or data corruption when using specific types of storage known as zoned devices. This affects systems that use encrypted storage on modern high-capacity drives that utilize zoned namespaces. An exploit could result in a complete system freeze or the silent corruption of files stored on the encrypted drive, potentially leading to permanent data loss or operational disruption.
Technical details
A vulnerability exists in the dm-crypt target of the Linux kernel when processing write BIOs for zoned devices. The issue stems from BIO splitting logic: when a large write BIO is split into smaller operations to fit internal limits, it can trigger a deadlock during queue freeze operations because the remainder BIO is re-issued from a zone write plug work context that calls blk_queue_enter(). Additionally, splitting zone append operations causes incorrect sector reporting to the issuer, leading to data corruption in file systems like XFS or Btrfs. The fix modifies get_max_request_sectors() to ensure entire BIOs are accepted without splitting for zoned targets and adjusts max_hw_sectors limits to prevent improper fragmentation.
Affected products
- Linux Linux Kernel 6.10 to 6.12.44
Timeline
- 2025-06-25: disclosed: Initial patch submission
- 2025-08-28: patched: Patches committed to stable trees
- 2025-09-11: advisory: CVE published