Junglewise Threat Intelligence

CVE-2026-90323: Linux kernel ublk buffer registration state machine race

CVE-2026-90323 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ublk (userspace block driver) subsystem contains a state management flaw in its automatic buffer registration feature. When invalid buffer addresses are provided, the system can enter a state where requests remain marked as active but the ring command completes abnormally, causing device teardown to hang and rendering the storage I/O path unresponsive.

Technical details

This is a race condition in the ublk automatic buffer registration (UBLK_F_AUTO_BUF_REG) code path. The vulnerability occurs because validation of buffer parameters happens after the UBLK_IO_FLAG_ACTIVE flag is set by ublk_fill_io_cmd(). If an invalid sqe->addr is provided, the uring_cmd completion fails but the I/O tag remains marked active, leaving inconsistent state during teardown. The fix reorders operations to validate the buffer (ublk_validate_io_buf) before applying it, ensuring no side effects from failed validation, and applies the same ordering discipline in the FETCH path to prevent io->buf corruption. This affects Linux kernel versions where the auto buffer register feature was introduced (5.19+).

Affected products

  • Linux Linux kernel 5.19+

Timeline

  • 2026-09-17: disclosed
  • 2026-07-30: other: Original commit authored 2026-07-30

References

Related threats