Executive brief
A vulnerability in the Linux kernel's storage subsystem (SCSI) can cause system processes to hang when removing storage devices. This occurs because certain internal commands become stuck in a queue during device recovery or removal. While primarily an availability issue, it can lead to service disruptions or system instability during hardware maintenance or failure scenarios.
Technical details
A logic error in the SCSI core's scsi_run_host_queues() function leads to a hang during device removal. The function previously used shost_for_each_device(), which relies on scsi_device_get() to iterate through devices. This iterator skips devices in the SDEV_CANCEL state (partially removed). If these devices have requeued requests from a prior host recovery state, those requests are never 'kicked' or processed, causing the removal process to wait indefinitely. The fix modifies the iteration logic to include all devices except those already in the SDEV_DEL state, ensuring that requeued commands are properly cleared even for devices undergoing removal.
Affected products
- Linux Linux Kernel 6.5 to 7.0.11
Timeline
- 2026-07-19: disclosed: CVE published and patches available in stable branches.
References
- https://git.kernel.org/stable/c/15fb19af49f2073ed77fad16aaabc648b0ca6800
- https://git.kernel.org/stable/c/475f2b37a78f4c698967a7f14f325f04e24c9175
- https://git.kernel.org/stable/c/7205b58702273baf21d6ba7992e6ba15852325f7
- https://git.kernel.org/stable/c/c740e13e7fe32d8e4d9a1699f65b8daf6709895a
- https://git.kernel.org/stable/c/d4dddfecdbb5467bef158d4e1486459808357fef