Race condition in Linux kernel - CVE-2026-68173
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the ublk driver recovery and device readiness handling in drivers/block/ublk_drv.c when processing user recovery state transitions. A local user can trigger recovery completion in an invalid state to cause a denial of service.
The issue can strand a request while holding its tag, causing subsequent fsync operations to block in uninterruptible sleep and device teardown to hang.