scsi: smartpqi: Fix device resources accessed after device removal
Summary
| CVE | CVE-2025-68371 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-12-24 11:16:00 UTC |
| Updated | 2026-07-14 13:17:58 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Fix device resources accessed after device removal Correct possible race conditions during device removal. Previously, a scheduled work item to reset a LUN could still execute after the device was removed, leading to use-after-free and other resource access issues. This race condition occurs because the abort handler may schedule a LUN reset concurrently with device removal via sdev_destroy(), leading to use-after-free and improper access to freed resources. - Check in the device reset handler if the device is still present in the controller's SCSI device list before running; if not, the reset is skipped. - Cancel any pending TMF work that has not started in sdev_destroy(). - Ensure device freeing in sdev_destroy() is done while holding the LUN reset mutex to avoid races with ongoing resets. |
Risk And Classification
EPSS: 0.001610000 probability, percentile 0.056980000 (date 2026-07-14)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 2d80f4054f7f901b8ad97358a9069616ac8524c7 7dfa5a5516ec3c6b9b6c22ee18f0eb2df3f38ef2 git | Not specified |
| CNA | Linux | Linux | affected 2d80f4054f7f901b8ad97358a9069616ac8524c7 6d2390653d82cad0e1ba2676e536dd99678f6ef1 git | Not specified |
| CNA | Linux | Linux | affected 2d80f4054f7f901b8ad97358a9069616ac8524c7 eccc02ba1747501d92bb2049e3ce378ba372f641 git | Not specified |
| CNA | Linux | Linux | affected 2d80f4054f7f901b8ad97358a9069616ac8524c7 4e1acf1b6dd6dd0495bda139daafd7a403ae2dc1 git | Not specified |
| CNA | Linux | Linux | affected 2d80f4054f7f901b8ad97358a9069616ac8524c7 1a5c5a2f88e839af5320216a02ffb075b668596a git | Not specified |
| CNA | Linux | Linux | affected 2d80f4054f7f901b8ad97358a9069616ac8524c7 b518e86d1a70a88f6592a7c396cf1b93493d1aab git | Not specified |
| CNA | Linux | Linux | affected 6.0 | Not specified |
| CNA | Linux | Linux | unaffected 6.0 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.160 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.120 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.63 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.17.13 6.17.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.2 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.19 * original_commit_for_fix | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIPLUS S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/6d2390653d82cad0e1ba2676e536dd99678f6ef1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| cert-portal.siemens.com/productcert/html/ssa-019113.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/7dfa5a5516ec3c6b9b6c22ee18f0eb2df3f38ef2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/eccc02ba1747501d92bb2049e3ce378ba372f641 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4e1acf1b6dd6dd0495bda139daafd7a403ae2dc1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b518e86d1a70a88f6592a7c396cf1b93493d1aab | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/1a5c5a2f88e839af5320216a02ffb075b668596a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.