Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-80589

block: stop the timeout timer when releasing a never added disk
Back to all
CVE

CVE-2026-80589

block: stop the timeout timer when releasing a never added disk

In the Linux kernel, the following vulnerability has been resolved:

block: stop the timeout timer when releasing a never added disk

diskrelease() undoes blkmqinitallocated_queue() for a disk whose

probe failed before adddisk(), but it only calls blkmqexitqueue().

Nothing there stops q->timeout, and that timer rolls forward: it stays

pending until it next expires, not until the last request completes.

So if the driver issued any I/O before adding the disk, the

request_queue is freed while still linked into a timer wheel bucket.

Commit 6f8191fdf41d ("block: simplify disk shutdown") dropped the

blkcleanupqueue() call that used to stop it.  _delgendisk() and

blkmqdestroy_queue() still do; only the probe failure path lost it.

nvme gets there because nvmeupdatens_info() submits Report Zones or

FDP io-mgmt-recv on ns->queue before the disk is added, so a later

failure - a concurrent reset setting NVMECTRLFROZEN, or

deviceadddisk() failing - lands in put_disk() with the timer armed:

  BUG: KASAN: slab-use-after-free in detachifpending+0x30c/0x340

  Write of size 8 at addr ffff888004d71310 by task kworker/u8:2/37

   _timerdelete_sync+0x156/0x240 kernel/time/timer.c:1621

   blksyncqueue+0x22/0x40 block/blk-core.c:222

   nvmesyncqueues+0x100/0x150 drivers/nvme/host/core.c:5362

   nvmeresetwork+0x138/0x930 drivers/nvme/host/pci.c:3264

  Allocated by task 34:

   _blkmqallocdisk+0x33/0x100 block/blk-mq.c:4462

   nvmeallocns+0x290/0x3870 drivers/nvme/host/core.c:4146

  Freed by task 0:

   blkfreequeue_rcu+0x3a/0x50 block/blk-core.c:254

   rcu_core+0xc10/0x1730 kernel/rcu/tree.c:2857

The queue being synced there is ctrl->admin_q, only a victim sharing a

timer wheel bucket with the freed queue's dangling entry; other runs

tripped in enqueuetimer(), runtimers() or blkmqtimeout_work().

Failing nvmeallocns() with a debug patch makes it deterministic: one

leaked timer trips KASAN within seconds, while 1987 patched releases

produced no splat.

Stop the timer and the queue work items before blkmqexit_queue(), like

blkmqdestroy_queue() does.

Found by FuzzNvme.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/1a0ae4d502062a2759f2a92d12bdeab3c64c7372, https://git.kernel.org/stable/c/26cb8ebbfaf713c82e142d08828d4d765057633b, https://git.kernel.org/stable/c/6ae7364f68e6c7af6b6df4bbb14040b89e5975d0, https://git.kernel.org/stable/c/6f06dbe5012c160e0dba418a5a9cb16c456ad46a, https://git.kernel.org/stable/c/93d620519d71dfc6ee64b5baea74f1d85d4439fb, https://git.kernel.org/stable/c/bb03b56d1d754908a37a160603be21769da423cf, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80589.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80589, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00701%
EPSS Percentile
0.51749%
Introduced Version
6f8191fdf41d3a53cc1d63fe2234e812c55a0092,5.19.12,d27b66257db183fe11c10f31246ae965adb005d3,6.0.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
26cb8ebbfaf713c82e142d08828d4d765057633b,5.20,6.1.184,6.6.153,6.12.105,6.18.46,7.1.10,6.1.187-1,6.12.107-1~deb12u1,6.12.105-1,6.8.0-1036.39,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek,1:6.1.186-228.374.amzn2023,1:1.0-0.amzn2023,1:6.18.48-107.148.amzn2023

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading