CVE-2026-53304 Details
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Resolve soft lockup issue when opening /dev/sgX The parameter def_reserved_size defines the default buffer size reserved for each Sg_fd and should be restricted to a range between 0 and 1,048,576 (see https://tldp.org/HOWTO/SCSI-Generic-HOWTO/proc.html). Although the function sg_proc_write_dressz enforces this limit, it is possible to bypass it by directly modifying the module parameter as shown below, which then causes a soft lockup: echo -1 > /sys/module/sg/parameters/def_reserved_size exec 4<> /dev/sg0 watchdog: BUG: soft lockup - CPU#5 stuck for 26 seconds! [bash:537] Modules loaded: CPU: 5 UID: 0 PID: 537 Command: bash, kernel version 6.19.0-rc3+ #134, PREEMPT disabled Hardware: QEMU Standard PC (i440FX + PIIX, 1996), BIOS version 1.16.1-2.fc37 dated 04/01/2014 ... Call Trace: sg_build_reserve+0x5c/0xa0 sg_add_sfp+0x168/0x270 sg_open+0x16e/0x340 chrdev_open+0xbe/0x230 do_dentry_open+0x175/0x480 vfs_open+0x34/0xf0 do_open+0x265/0x3d0 path_openat+0x110/0x290 do_filp_open+0xc3/0x170 do_sys_openat2+0x71/0xe0 __x64_sys_openat+0x6d/0xa0 do_syscall_64+0x62/0x310 entry_SYSCALL_64_after_hwframe+0x76/0x7e The fix is to use module_param_cb to validate and reject invalid values assigned to def_reserved_size.
A soft lockup vulnerability has been identified in the Linux kernel's SCSI generic (sg) driver. This issue arises when the 'def_reserved_size' parameter, which defines the default buffer size for Sg_fd, is set outside the recommended range of 0 to 1,048,576 bytes. Although the driver includes a function to enforce this limit, it can be bypassed by directly modifying the parameter, leading to a soft lockup. The problem was observed in a QEMU virtual machine running Linux kernel 6.19.0-rc3+.
The vulnerability has been addressed by modifying the driver to use a callback function for the 'def_reserved_size' parameter. This change allows the driver to validate the parameter's value and reject any invalid settings before they can cause a lockup.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/1afd963fcd963db0dc5d47df6dfcf010c9c4647e | kernel.org | Patch |
| https://git.kernel.org/stable/c/3d74e0654ac908c65a8f20373091826fe43b1363 | kernel.org | Patch |
| https://git.kernel.org/stable/c/9676ca7b1ef31a3a65b3e61e7ce3b54ce7364202 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c47ccfb3d80dfed522ca06a5954ac97488d78c5a | kernel.org | Patch |
| https://git.kernel.org/stable/c/c5f4a211e82d04ccc1809311322c47023bbe66e2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d06a310b45e153872033dd0cf19d5a2279121099 | kernel.org | Patch |
| https://git.kernel.org/stable/c/fe671d3c84ffb1b763d590c25195755adeaadaba | kernel.org | Patch |
| https://git.kernel.org/stable/c/feade299e932967de27519338d41de348fb5b061 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-667 | Improper Locking | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.19, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.141 >= 6.7, < 6.12.91 >= 6.13, < 6.18.33 >= 6.19, < 7.0.10 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | Initial Analysis | [email protected] |
| Jun 26, 2026 | New CVE Received | kernel.org |