PT-2026-97981 · Linux · Linux Kernel

CVE-2026-93781

·

Published

2026-09-24

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A circular dependency exists in the SCSI core during error handling. The function scsi eh lock door(), called by scsi restart operations() while the host is in the SHOST RECOVERY state, uses scsi alloc request() to allocate a request. Because it does so without specific flags, blk mq get tag() may block while waiting for a free sched tag if all tags are occupied. These tags may be held by commands requeued by scsi eh flush done q(), which cannot be dispatched until the host returns to SHOST RUNNING and scsi run host queues() is called. Since this transition only occurs after scsi eh lock door() returns, a deadlock occurs. This is particularly critical for devices with a single driver tag, such as USB storage, resulting in I/O that cannot be submitted.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-93781

Affected Products

Linux Kernel