Security Advisory

CVE-2025-38326

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-07-10 08:15:00
Last updated 2026-05-11 21:25:49
Assigner Linux
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: aoe: clean device rq_list in aoedev_downdev() An aoe devices rq_list contains accepted block requests that are waiting to be transmitted to the aoe target. This queue was added as part of the conversion to blk_mq. However, the queue was not cleaned out when an aoe device is downed which caused blk_mq_freeze_queue() to sleep indefinitely waiting for those requests to complete, causing a hang. This fix cleans out the queue before calling blk_mq_freeze_queue().