Improper handling of exceptional conditions in Linux kernel - CVE-2026-64326
Published: July 27, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper exceptional condition handling in bdev_mark_dead() when processing surprise removal of a block device. A local user can trigger surprise device removal to cause a denial of service.
The issue can hang indefinitely while waiting for writeback that can no longer complete, wedging the reset worker and tasks waiting on it.
How to mitigate CVE-2026-64326
Sources
- https://git.kernel.org/stable/c/49f06cff50a4ccf3b7a1a662ceb892b3b21a527a
- https://git.kernel.org/stable/c/9818bcae3c0ca1dde4b9a334125c46676e0a9b29
- https://git.kernel.org/stable/c/aa4c4a9315764b2b7a7182e72cc5ea87520436b4
- https://git.kernel.org/stable/c/d6998ddd507c81e3829489a6ead23f17f5acb7fe
- https://git.kernel.org/stable/c/f41cf35ee2a1e31374b3f54e7579c55153506e70