CVE-2025-38302 – Linux Kernel Block Driver Freezing Protection Denial of Service

The following table lists the changes that have been made to the
CVE-2025-38302 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jul. 10, 2025

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved:

    block: don’t use submit_bio_noacct_nocheck in blk_zone_wplug_bio_work

    Bios queued up in the zone write plug have already gone through all all
    preparation in the submit_bio path, including the freeze protection.

    Submitting them through submit_bio_noacct_nocheck duplicates the work
    and can can cause deadlocks when freezing a queue with pending bio
    write plugs.

    Go straight to ->submit_bio or blk_mq_submit_bio to bypass the
    superfluous extra freeze protection and checks.

    Added Reference https://git.kernel.org/stable/c/0fccb6773b1f4f992e435582cf8e050de421b678
    Added Reference https://git.kernel.org/stable/c/6ffae5d53f704d300cc73b06b4ea99e4507f7cf1
    Added Reference https://git.kernel.org/stable/c/cf625013d8741c01407bbb4a60c111b61b9fa69d
Share the Post:

Related Posts