Review reviewHigh

CVE-2025-68218

Linux

In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: fix lockdep WARN due to partition scan work Blktests test cases nvme/014, 057 and 058 fail occasionally due to a lockdep WARN. As reported in the Closes tag URL, the WARN indicates that a deadlock can happen due to the dependency among disk->open_mutex, kblockd workqueue completion and partition_scan_work completion. To avoid the lockdep WARN and the potential deadlock, cut the dependency by running the partition_scan_work not by kblockd workqueue but by nvme_wq.

CVSS
7.5
EPSS
0.46%
37.5% percentile
CISA KEV
Not listed
Published
2025.12.16
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.46%
Technical severityCVSS 7.5

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: fix lockdep WARN due to partition scan work Blktests test cases nvme/014, 057 and 058 fail occasionally due to a lockdep WARN. As reported in the Closes tag URL, the WARN indicates that a deadlock can happen due to the dependency among disk->open_mutex, kblockd workqueue completion and partition_scan_work completion. To avoid the lockdep WARN and the potential deadlock, cut the dependency by running the partition_scan_work not by kblockd workqueue but by nvme_wq.

Affected product and versions

Product
Linux
Affected versions
>= 60de2e03f984cfbcdc12fa552f95087c35a05a98 < 89456dab7ba5ab63d60945440926673a3205e829, >= 4a57f42e5ed42cb8f1beb262c4f6d3e698939e4e < e2a897ad5f538d314955c747a0a2edb184fcdecd, >= 1f021341eef41e77a633186e9be5223de2ce5d48 < ef4ab2a8abe554379e10303ae86f7c501336ba0d, >= 1f021341eef41e77a633186e9be5223de2ce5d48 < b03eb63288a8ffe3adfb34e68309c8e2edb06d0b, >= 1f021341eef41e77a633186e9be5223de2ce5d48 < 6d87cd5335784351280f82c47cc8a657271929c3, >= a91b7eddf45afeeb9c5ece11dddff5de0921b00f, >= 6.1.118 < 6.1.159, >= 6.6.62 < 6.6.118, >= 6.11.9 < 6.12, >= 6.12
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
Not available