CVE-2025-71117Improper Locking in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 96.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14
Latest updateApr 17

Description

In the Linux kernel, the following vulnerability has been resolved: block: Remove queue freezing from several sysfs store callbacks Freezing the request queue from inside sysfs store callbacks may cause a deadlock in combination with the dm-multipath driver and the queue_if_no_path option. Additionally, freezing the request queue slows down system boot on systems where sysfs attributes are set synchronously. Fix this by removing the blk_mq_freeze_queue() / blk_mq_unfreeze_queue() calls from t

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages8 packages

Linuxlinux/linux_kernel6.11.06.18.3
NVDlinux/linux_kernel6.11.16.18.3+2
Debianlinux/linux_kernel< 6.18.3-1
CVEListV5linux/linuxaf2814149883e2c1851866ea2afcd8eadc040f793997b3147c7b68b0308378fa95a766015f8ceb1c+2
debiandebian/linux< linux 6.18.3-1 (forky)

Patches

🔴Vulnerability Details

3
GHSA
GHSA-c5ch-44q8-865h: In the Linux kernel, the following vulnerability has been resolved: block: Remove queue freezing from several sysfs store callbacks Freezing the req2026-01-14
OSV
block: Remove queue freezing from several sysfs store callbacks2026-01-14
OSV
CVE-2025-71117: In the Linux kernel, the following vulnerability has been resolved: block: Remove queue freezing from several sysfs store callbacks Freezing the reque2026-01-14

📋Vendor Advisories

5
Ubuntu
Linux kernel (GCP) vulnerabilities2026-04-17
Ubuntu
Linux kernel (Real-time) vulnerabilities2026-04-17
Ubuntu
Linux kernel vulnerabilities2026-04-16
Red Hat
kernel: Linux kernel: Denial of Service via deadlock in block layer sysfs store callbacks2026-01-14
Debian
CVE-2025-71117: linux - In the Linux kernel, the following vulnerability has been resolved: block: Remo...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-71117 Impact, Exploitability, and Mitigation Steps | Wiz