Executive brief
The Linux kernel's UFS (Ultra FS) storage driver contains a potential null pointer dereference bug in its completion queue event handler. When processing invalid completion tags from storage devices, the error reporting code could crash the kernel if it attempts to access a null completion queue entry, resulting in system instability or denial of service on servers using UFS storage.
Technical details
The vulnerability is a null pointer dereference in the `ufshcd_compl_one_cqe()` function within the UFS host controller driver. When the single-doorbell completion path receives an invalid completion tag with no associated command, the WARN_ONCE() macro attempted to dereference a NULL CQE (completion queue entry) pointer while constructing the warning message. The fix adds a null check (`cqe ?`) before dereferencing the pointer and includes the invalid tag value in the error message. This is a defensive programming fix rather than a critical exploitable vulnerability; local code execution or denial of service would require triggering this specific error path through malformed device responses or kernel manipulation.
Affected products
- Linux Linux kernel affected versions including 6.0 through 6.19 and 5.x series
Timeline
- 2026-09-17: disclosed
- 2026-07-26: patched