CVE-2025-68178

UNRATEDCVSS · not yet scored
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • No CVSS published and no exploitation signals yet
CISA-KEV: Not listedEPSS PROB: 0%CVSS v2: Exploit: None knownExposed: 0

A fix is available — apply it.

In the Linux kernel, the following vulnerability has been resolved:

blk-cgroup: fix possible deadlock while configuring policy

Following deadlock can be triggered easily by lockdep:

WARNING: possible circular locking dependency detected 6.17.0-rc3-00124-ga12c2658ced0 #1665 Not tainted ------------------------------------------------------ check/1334 is trying to acquire lock: ff1100011d9d0678 (&q->sysfs_lock){+.+.}-{4:4}, at: blk_unregister_queue+0x53/0x180

but task is already holding lock: ff1100011d9d00e0 (&q->q_usage_counter(queue)#3){++++}-{0:0}, at: del_gendisk+0xba/0x110

which lock already depends on the new lock.

the existing dependency chain (in reverse order) is:

-> #2 (&q->q_usage_counter(queue)#3){++++}-{0:0}: blk_queue_enter+0x40b/0x470 blkg_conf_prep+0x7b/0x3c0 tg_set_limit+0x10a/0x3e0 cgroup_file_write+0xc6/0x420 kernfs_fop_write_iter+0x189/0x280 vfs_write+0x256/0x490 ksys_write+0x83/0x190 __x64_sys_write+0x21/0x30 x64_sys_call+0x4608/0x4630 do_syscall_64+0xdb/0x6b0 entry_SYSCALL_64_after_hwframe+0x76/0x7e

-> #1 (&q->rq_qos_mutex){+.+.}-{4:4}: __mutex_lock+0xd8/0xf50 mutex_lock_nested+0x2b/0x40 wbt_init+0x17e/0x280 wbt_enable_default+0xe9/0x140 blk_register_queue+0x1da/0x2e0 __add_disk+0x38c/0x5d0 add_disk_fwnode+0x89/0x250 device_add_disk+0x18/0x30 virtblk_probe+0x13a3/0x1800 virtio_dev_probe+0x389/0x610 really_probe+0x136/0x620 __driver_probe_device+0xb3/0x230 driver_probe_device+0x2f/0xe0 __driver_attach+0x158/0x250 bus_for_each_dev+0xa9/0x130 driver_attach+0x26/0x40 bus_add_driver+0x178/0x3d0 driver_register+0x7d/0x1c0 __register_virtio_driver+0x2c/0x60 virtio_blk_init+0x6f/0xe0 do_one_initcall+0x94/0x540 kernel_init_freeable+0x56a/0x7b0 kernel_init+0x2b/0x270 ret_from_fork+0x268/0x4c0 ret_from_fork_asm+0x1a/0x30

-> #0 (&q->sysfs_lock){+.+.}-{4:4}: __lock_acquire+0x1835/0x2940 lock_acquire+0xf9/0x450 __mutex_lock+0xd8/0xf50 mutex_lock_nested+0x2b/0x40 blk_unregister_queue+0x53/0x180 __del_gendisk+0x226/0x690 del_gendisk+0xba/0x110 sd_remove+0x49/0xb0 [sd_mod] device_remove+0x87/0xb0 device_release_driver_internal+0x11e/0x230 device_release_driver+0x1a/0x30 bus_remove_device+0x14d/0x220 device_del+0x1e1/0x5a0 __scsi_remove_device+0x1ff/0x2f0 scsi_remove_device+0x37/0x60 sdev_store_delete+0x77/0x100 dev_attr_store+0x1f/0x40 sysfs_kf_write+0x65/0x90 kernfs_fop_write_iter+0x189/0x280 vfs_write+0x256/0x490 ksys_write+0x83/0x190 __x64_sys_write+0x21/0x30 x64_sys_call+0x4608/0x4630 do_syscall_64+0xdb/0x6b0 entry_SYSCALL_64_after_hwframe+0x76/0x7e

other info that might help us debug this:

Chain exists of: &q->sysfs_lock --> &q->rq_qos_mutex --> &q->q_usage_counter(queue)#3

Possible unsafe locking scenario:

CPU0 CPU1 ---- ---- lock(&q->q_usage_counter(queue)#3); lock(&q->rq_qos_mutex); lock(&q->q_usage_counter(queue)#3); lock(&q->sysfs_lock);

Root cause is that queue_usage_counter is grabbed with rq_qos_mutex held in blkg_conf_prep(), while queue should be freezed before rq_qos_mutex from other context.

The blk_queue_enter() from blkg_conf_prep() is used to protect against policy deactivation, which is already protected with blkcg_mutex, hence convert blk_queue_enter() to blkcg_mutex to fix this problem. Meanwhile, consider that blkcg_mutex is held after queue is freezed from policy deactivation, also convert blkg_alloc() to use GFP_NOIO.

CVSS v3
EchelonGraph score
Not yet assessedNo source has published severity data for this CVE yet — no CVSS score from NVD or a CNA, no GitHub advisory, and it is not in CISA KEV. This is not a rating of zero; we cannot assess it yet.
EG Score
EG Risk
EPSS PROB
0%
EPSS %ILE
7%
KEV
Not listed

Published

December 16, 2025

Last Modified

April 15, 2026

Patch Availability(16)

Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.

All Vendor Advisories

(15)

Data Freshness Timeline

(refreshed 9× in last 7d / 42× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

Showing the most recent 100 of 130 total refreshes for this CVE.

  1. 2026-08-01 04:15 UTCEPSS rescore
  2. 2026-07-30 16:27 UTCEPSS rescore
  3. 2026-07-30 01:30 UTCEPSS rescore
  4. 2026-07-27 14:13 UTCEPSS rescore
  5. 2026-07-27 04:39 UTCOSV refresh
  6. 2026-07-26 14:54 UTCEPSS rescore
  7. 2026-07-26 14:54 UTCEPSS rescore
  8. 2026-07-25 14:17 UTCEPSS rescore
  9. 2026-07-25 14:17 UTCEPSS rescore
  10. 2026-07-24 14:17 UTCEPSS rescore
  11. 2026-07-23 14:18 UTCEPSS rescore
  12. 2026-07-23 14:18 UTCEPSS rescore
  13. 2026-07-23 03:02 UTCEG score recompute
  14. 2026-07-22 14:08 UTCEPSS rescore
  15. 2026-07-21 15:24 UTCEPSS rescore
  16. 2026-07-20 17:08 UTCEPSS rescore
  17. 2026-07-19 14:30 UTCEPSS rescore
  18. 2026-07-19 14:30 UTCEPSS rescore
  19. 2026-07-19 02:28 UTCEPSS rescore
  20. 2026-07-19 02:28 UTCEPSS rescore
  21. 2026-07-18 10:04 UTCEPSS rescore
  22. 2026-07-18 10:04 UTCEPSS rescore
  23. 2026-07-16 17:02 UTCEPSS rescore
  24. 2026-07-16 17:02 UTCEPSS rescore
  25. 2026-07-15 16:57 UTCEPSS rescore
Show 75 more
  1. 2026-07-15 16:57 UTCEPSS rescore
  2. 2026-07-15 02:00 UTCEPSS rescore
  3. 2026-07-15 01:59 UTCEPSS rescore
  4. 2026-07-12 05:46 UTCEPSS rescore
  5. 2026-07-12 05:46 UTCEPSS rescore
  6. 2026-07-11 08:27 UTCEPSS rescore
  7. 2026-07-11 08:27 UTCEPSS rescore
  8. 2026-07-09 23:17 UTCOSV refresh
  9. 2026-07-09 19:10 UTCEPSS rescore
  10. 2026-07-08 15:15 UTCEPSS rescore
  11. 2026-07-07 13:46 UTCEPSS rescore
  12. 2026-07-06 16:27 UTCEPSS rescore
  13. 2026-07-06 02:23 UTCEPSS rescore
  14. 2026-07-05 02:30 UTCEPSS rescore
  15. 2026-07-05 02:30 UTCEPSS rescore
  16. 2026-07-04 06:31 UTCEPSS rescore
  17. 2026-07-04 06:31 UTCEPSS rescore
  18. 2026-07-01 15:06 UTCEPSS rescore
  19. 2026-06-30 23:22 UTCEPSS rescore
  20. 2026-06-30 23:22 UTCEPSS rescore
  21. 2026-06-29 14:06 UTCEPSS rescore
  22. 2026-06-29 14:06 UTCEPSS rescore
  23. 2026-06-28 14:07 UTCEPSS rescore
  24. 2026-06-28 14:07 UTCEPSS rescore
  25. 2026-06-28 04:56 UTCEPSS rescore
  26. 2026-06-28 04:56 UTCEPSS rescore
  27. 2026-06-27 03:08 UTCEPSS rescore
  28. 2026-06-25 13:49 UTCEPSS rescore
  29. 2026-06-25 13:49 UTCEPSS rescore
  30. 2026-06-24 14:05 UTCEPSS rescore
  31. 2026-06-24 14:04 UTCEPSS rescore
  32. 2026-06-23 21:32 UTCEPSS rescore
  33. 2026-06-22 14:25 UTCEPSS rescore
  34. 2026-06-22 14:25 UTCEPSS rescore
  35. 2026-06-21 14:56 UTCEPSS rescore
  36. 2026-06-21 14:56 UTCEPSS rescore
  37. 2026-06-21 09:31 UTCOSV refresh
  38. 2026-06-21 01:59 UTCEPSS rescore
  39. 2026-06-21 01:59 UTCEPSS rescore
  40. 2026-06-19 19:25 UTCEPSS rescore
  41. 2026-06-19 19:25 UTCEPSS rescore
  42. 2026-06-18 17:52 UTCEPSS rescore
  43. 2026-06-18 17:52 UTCEPSS rescore
  44. 2026-06-17 17:53 UTCEPSS rescore
  45. 2026-06-16 17:52 UTCEPSS rescore
  46. 2026-06-15 17:48 UTCEPSS rescore
  47. 2026-06-15 17:48 UTCEPSS rescore
  48. 2026-06-14 23:18 UTCEPSS rescore
  49. 2026-06-13 23:00 UTCEPSS rescore
  50. 2026-06-13 23:00 UTCEPSS rescore
  51. 2026-06-12 23:11 UTCEPSS rescore
  52. 2026-06-11 14:00 UTCEPSS rescore
  53. 2026-06-10 22:18 UTCEPSS rescore
  54. 2026-06-10 22:18 UTCEPSS rescore
  55. 2026-06-10 13:22 UTCEPSS rescore
  56. 2026-06-08 14:17 UTCEPSS rescore
  57. 2026-06-08 14:16 UTCEPSS rescore
  58. 2026-06-07 15:24 UTCEPSS rescore
  59. 2026-06-07 15:24 UTCEPSS rescore
  60. 2026-06-06 13:47 UTCEPSS rescore
  61. 2026-06-06 13:47 UTCEPSS rescore
  62. 2026-06-05 22:46 UTCEPSS rescore
  63. 2026-06-05 22:46 UTCEPSS rescore
  64. 2026-06-05 06:10 UTCEPSS rescore
  65. 2026-06-05 06:10 UTCEPSS rescore
  66. 2026-06-04 13:12 UTCEPSS rescore
  67. 2026-06-04 13:12 UTCEPSS rescore
  68. 2026-06-02 20:13 UTCEPSS rescore
  69. 2026-06-02 20:12 UTCEPSS rescore
  70. 2026-06-02 00:09 UTCOSV refresh
  71. 2026-06-01 13:51 UTCEPSS rescore
  72. 2026-06-01 13:51 UTCEPSS rescore
  73. 2026-05-31 22:30 UTCEPSS rescore
  74. 2026-05-31 22:30 UTCEPSS rescore
  75. 2026-05-31 00:16 UTCEPSS rescore

Frequently asked(4)

What is CVE-2025-68178?
CVE-2025-68178 is a publicly disclosed vulnerability published on December 16, 2025. In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix possible deadlock while configuring policy Following deadlock can be triggered easily by lockdep: WARNING: possible circular locking dependency detected 6.17.0-rc3-00124-ga12c2658ced0 #1665 Not tainted…
When was CVE-2025-68178 disclosed?
CVE-2025-68178 was first published in the National Vulnerability Database on December 16, 2025, with the most recent update on April 15, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2025-68178 actively exploited?
CVE-2025-68178 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0% probability of exploitation in the next 30 days, which ranks it in the top 92.8% of all scored CVEs.
How do I remediate CVE-2025-68178?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2025-68178, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2025-68178

Explore →

Is Your Infrastructure Affected by CVE-2025-68178?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.