CVE-2025-21817
Executive Summary
CVE-2025-21817 exposes a deadlock risk in the Linux kernel when sysfs store callbacks run while the block queue is frozen. Memory allocations using GFP_KERNEL can trigger direct reclaim, potentially causing a deadlock. The patch marks these allocations with GFP_NOIO to prevent direct reclaim during the frozen state, restoring kernel stability.
Authoritative CVE Metadata - CVSS Base Score: 5.5 (MEDIUM) - Published: 2025-02-27T20:16:04.243 - Last Modified: 2026-09-07T16:17:27.213
Original Description: In the Linux kernel, the following vulnerability has been resolved:
block: mark GFP_NOIO around sysfs ->store()
sysfs ->store is called with queue freezed, meantime we have several ->store() callbacks(update_nr_requests, wbt, scheduler) to allocate memory with GFP_KERNEL which may run into direct reclaim code path, then potential deadlock can be caused.
Fix the issue by marking NOIO around sysfs ->store()
"Imagination is not a talent of some men but is the health of every man."
— Ralph Waldo Emerson