CVE-2026-74392

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/08/2026
Last modified:
15/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> dm: limit target bio polling to one shot<br /> <br /> dm_poll_bio() is the -&gt;poll_bio() callback for a stacked dm device.<br /> The caller only knows about the dm queue, so it may decide to do a<br /> spinning poll if it thinks a single queue is being polled. Passing those<br /> flags unchanged to the mapped clone lets blk_mq_poll() spin on a target<br /> queue from inside dm_poll_bio().<br /> <br /> With io_uring IOPOLL on a dm-stripe target this can keep a task in<br /> <br /> dm_poll_bio() -&gt; bio_poll() -&gt; blk_mq_poll()<br /> <br /> long enough to trigger an RCU CPU stall, before io_uring gets back to<br /> io_iopoll_check() and its need_resched() check.<br /> <br /> Keep dm&amp;#39;s -&gt;poll_bio() bounded by forcing one-shot polling for target<br /> bios. The caller can invoke dm_poll_bio() again if it wants to keep<br /> polling, and it also gets a chance to reap completions or reschedule<br /> between passes.

Impact