Junglewise Threat Intelligence

CVE-2026-53124: Linux Kernel ublk hung IO during server recovery

CVE-2026-53124 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's ublk (Userspace Block Device) framework could cause system operations to hang or fail to complete. This occurs when a ublk server process crashes during device recovery, leaving certain input/output (IO) commands in a state where they cannot be properly canceled or finished. This could lead to resource exhaustion or unresponsive storage devices, potentially impacting system stability and availability.

Technical details

A vulnerability in `drivers/block/ublk_drv.c` in the Linux kernel stems from improper management of the `UBLK_IO_FLAG_CANCELED` flag. Previously, per-IO canceled flags were only reset once all IOs for a specific queue were fetched. If a ublk server crashes after fetching only a subset of IOs during recovery, the remaining outstanding commands retain the canceled flag. This prevents `ublk_cancel_cmd` from executing `io_uring_cmd_done`, causing the commands to remain in an indefinite outstanding state. The fix involves resetting the per-IO cancel flags immediately upon each individual IO fetch. Patches have been merged into various stable branches including 6.14.x and 7.x.

Affected products

  • Linux Linux Kernel 6.14.6, 6.15, 7.0.10

Timeline

  • 2026-04-05: other: Patch submitted by developer
  • 2026-06-24: disclosed: CVE published

References

Related threats