ACK: [SRU][J][PATCH 0/1] CVE-2025-37861

Andrei Gherzan andrei.gherzan at canonical.com
Tue Sep 15 12:33:45 UTC 2026


On 26/09/10 01:59AM, Cengiz Can via kernel-team wrote:
> https://ubuntu.com/security/CVE-2025-37861
> 
> [ Impact ]
> 
> In the Linux kernel, the following vulnerability has been resolved:
> 
> scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue
> 
> When the task management thread processes reply queues while the reset thread
> resets them, the task management thread accesses an invalid queue ID (0xFFFF),
> set by the reset thread, which points to unallocated memory, causing a crash.
> 
> Add flag 'io_admin_reset_sync' to synchronize access between the reset, I/O,
> and admin threads. Before a reset, the reset handler sets this flag to block
> I/O and admin processing threads. If any thread bypasses the initial check, the
> reset thread waits up to 10 seconds for processing to finish. If the wait
> exceeds 10 seconds, the controller is marked as unrecoverable.
> 
> [ Fix ]
> 
> jammy/linux: backported from f195fc060c73
> 
> [ Test Plan ]
> 
> Build and boot tested.
> 
> [ Where Problems Could Occur ]
> 
> A regression would only surface on systems using the mpi3mr driver, which
> drives Broadcom MPI 3.0 storage controllers (SAS/SATA/NVMe host bus adapters
> and RAID controllers); the risk is highest during controller reset or task
> management events, where the added synchronization flag could in theory stall
> I/O or admin processing or, if the 10 second wait elapses, mark a controller
> unrecoverable. Systems without such Broadcom controllers do not load this
> driver and are unaffected.
> 
> [ Other Info ]
> 
> Kybele flow-v11-25-ga27c0fa6. Reference: 57598f19/v1

Acked-by: Andrei Gherzan <andrei.gherzan at canonical.com>

-- 
Andrei Gherzan
gpg: rsa4096/D4D94F67AD0E9640
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20260915/dea2a6c4/attachment.sig>


More information about the kernel-team mailing list