cbcvebase.
CVE-2025-68310
published 2025-12-16

CVE-2025-68310: In the Linux kernel, the following vulnerability has been resolved: s390/pci: Avoid deadlock between PCI error recovery and mlx5 crdump Do not block PCI config…

PriorityP422high7.8
EPSS
0.17%
6.6th percentile
In the Linux kernel, the following vulnerability has been resolved: s390/pci: Avoid deadlock between PCI error recovery and mlx5 crdump Do not block PCI config accesses through pci_cfg_access_lock() when executing the s390 variant of PCI error recovery: Acquire just device_lock() instead of pci_dev_lock() as powerpc's EEH and generig PCI AER processing do. During error recovery testing a pair of tasks was reported to be hung: mlx5_core 0000:00:00.1: mlx5_health_try_recover:338:(pid 5553): health recovery flow aborted, PCI reads still not working INFO: task kmcheck:72 blocked for more than 122 seconds. Not tainted 5.14.0-570.12.1.bringup7.el9.s390x #1 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:kmcheck state:D stack:0 pid:72 tgid:72 ppid:2 flags:0x00000000 Call Trace: [] __schedule+0x2a0/0x590 [] schedule+0x36/0xe0 [] schedule_preempt_disabled+0x22/0x30 [] __mutex_lock.constprop.0+0x484/0x8a8 [] mlx5_unload_one+0x34/0x58 [mlx5_core] [] mlx5_pci_err_detected+0x94/0x140 [mlx5_core] [] zpci_event_attempt_error_recovery+0xf2/0x398 [] __zpci_event_error+0x23a/0x2c0 INFO: task kworker/u1664:6:1514 blocked for more than 122 seconds. Not tainted 5.14.0-570.12.1.bringup7.el9.s390x #1 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:kworker/u1664:6 state:D stack:0 pid:1514 tgid:1514 ppid:2 flags:0x00000000 Workqueue: mlx5_health0000:00:00.0 mlx5_fw_fatal_reporter_err_work [mlx5_core] Call Trace: [] __schedule+0x2a0/0x590 [] schedule+0x36/0xe0 [] pci_wait_cfg+0x80/0xe8 [] pci_cfg_access_lock+0x74/0x88 [] mlx5_vsc_gw_lock+0x36/0x178 [mlx5_core] [] mlx5_crdump_collect+0x34/0x1c8 [mlx5_core] [] mlx5_fw_fatal_reporter_dump+0x6a/0xe8 [mlx5_core] [] devlink_health_do_dump.part.0+0x82/0x168 [] devlink_health_report+0x19a/0x230 [] mlx5_fw_fatal_reporter_err_work+0xba/0x1b0 [mlx5_core] No kernel log of the exact same error with an upstream kernel is available - but the very same deadlock situation can be constructed t

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 4cdf2f4e24ff0d345fc36ef6d6aec059333a261e < d0df2503bc3c2be385ca2fd96585daad1870c7c5d0df2503bc3c2be385ca2fd96585daad1870c7c5
linuxlinux>= 4cdf2f4e24ff0d345fc36ef6d6aec059333a261e < b63c061be622b17b495cbf78a6d5f2d4c3147f8eb63c061be622b17b495cbf78a6d5f2d4c3147f8e
linuxlinux>= 4cdf2f4e24ff0d345fc36ef6d6aec059333a261e < 3591d56ea9bfd3e7fbbe70f749bdeed689d415f93591d56ea9bfd3e7fbbe70f749bdeed689d415f9
linuxlinux>= 4cdf2f4e24ff0d345fc36ef6d6aec059333a261e < 54f938d9f5693af8ed586a08db4af5d9da1f0f2d54f938d9f5693af8ed586a08db4af5d9da1f0f2d
linuxlinux>= 4cdf2f4e24ff0d345fc36ef6d6aec059333a261e < 0fd20f65df6aa430454a0deed8f43efa91c548350fd20f65df6aa430454a0deed8f43efa91c54835
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

vendor_ubuntu7.8HIGH
osv3.2LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.