[SRU][J][PATCH 0/1] CVE-2025-37861
Cengiz Can
cengiz.can at canonical.com
Thu Sep 10 01:59:05 UTC 2026
https://ubuntu.com/security/CVE-2025-37861
[ Impact ]
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue
When the task management thread processes reply queues while the reset thread
resets them, the task management thread accesses an invalid queue ID (0xFFFF),
set by the reset thread, which points to unallocated memory, causing a crash.
Add flag 'io_admin_reset_sync' to synchronize access between the reset, I/O,
and admin threads. Before a reset, the reset handler sets this flag to block
I/O and admin processing threads. If any thread bypasses the initial check, the
reset thread waits up to 10 seconds for processing to finish. If the wait
exceeds 10 seconds, the controller is marked as unrecoverable.
[ Fix ]
jammy/linux: backported from f195fc060c73
[ Test Plan ]
Build and boot tested.
[ Where Problems Could Occur ]
A regression would only surface on systems using the mpi3mr driver, which
drives Broadcom MPI 3.0 storage controllers (SAS/SATA/NVMe host bus adapters
and RAID controllers); the risk is highest during controller reset or task
management events, where the added synchronization flag could in theory stall
I/O or admin processing or, if the 10 second wait elapses, mark a controller
unrecoverable. Systems without such Broadcom controllers do not load this
driver and are unaffected.
[ Other Info ]
Kybele flow-v11-25-ga27c0fa6. Reference: 57598f19/v1
More information about the kernel-team
mailing list