Database/Kernel, userspace & hypervisor
Linux kernel SCSI core: blocking tag allocation during error recovery can deadlock the EH thread
Impact
During SCSI error recovery the host sits in SHOST_RECOVERY while scsi_eh_lock_door() allocates a request with blocking semantics. If every tag is held by commands that scsi_eh_flush_done_q() just requeued, those commands cannot be dispatched until the error handler returns, and the error handler cannot return until a tag frees - a circular wait. The upstream commit says this is a guaranteed deadlock on devices with a single driver tag and that it was reproduced in a real environment. On a GPU node the consequence is availability: the error handler thread hangs and I/O to that host never resumes, so a node whose local or attached storage trips error recovery stops making progress and has to be rebooted rather than drained cleanly. There is no indication in the record that an unprivileged tenant can trigger this on purpose; it depends on a device actually entering error handling.
Who can reach it
Not a remote or tenant-reachable attack path in the record. Requires a SCSI device on the node to enter error recovery while its tags are exhausted; no authentication concept applies.
What to do
Take the stable kernel containing the BLK_MQ_REQ_NOWAIT fix for scsi_eh_lock_door() (five stable branches carry it, linked below). A kernel update means draining the node and rebooting it; there is no runtime mitigation other than avoiding single-tag SCSI devices on the host. No fixed distro version is named in the record.
References
Related entries
- Linux kernel BPF: sysctl value replaced by a BPF program is not NUL-terminated, giving out-of-bounds readsCVE-2026-97420 · Linux kernel BPF (bpf_sysctl_set_new_value replacement buffer)Unscored
- Linux kernel net/rds: unprivileged container reads every RDS socket and connection on the hostCVE-2026-97476 · Linux kernel net/rds RDS_INFO_* getsockopt (missing netns filtering)Unscored
- Linux kernel net/rds: RDS-over-IB shutdown sleeps in a shared worker and hangs fabric teardownCVE-2026-97491 · Linux kernel net/rds over InfiniBand (rds_ib_conn_path_shutdown sleeping in the shutdown worker)Unscored
- Linux PCI sysfs: BAR resize via resourceN_resize had no CAP_SYS_ADMIN checkCVE-2026-97505 · Linux kernel PCI sysfs (resourceN_resize, __resource_resize_store)Unscored
- Linux kernel qla2xxx: unvalidated FC BSG request length causes out-of-bounds heap readsCVE-2026-97529 · Linux kernel qla2xxx (FC BSG vendor command request_len validation)Unscored
- Linux kernel qla2xxx: FC frame payload aliasing 0xDEADDEAD spins the interrupt handler into a CPU soft lockupCVE-2026-97530 · Linux kernel qla2xxx (continuation IOCB signature poll in interrupt context)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.