{"id":"DEBIAN-CVE-2025-38063","details":"In the Linux kernel, the following vulnerability has been resolved:  dm: fix unconditional IO throttle caused by REQ_PREFLUSH  When a bio with REQ_PREFLUSH is submitted to dm, __send_empty_flush() generates a flush_bio with REQ_OP_WRITE | REQ_PREFLUSH | REQ_SYNC, which causes the flush_bio to be throttled by wbt_wait().  An example from v5.4, similar problem also exists in upstream:      crash\u003e bt 2091206     PID: 2091206  TASK: ffff2050df92a300  CPU: 109  COMMAND: \"kworker/u260:0\"      #0 [ffff800084a2f7f0] __switch_to at ffff80004008aeb8      #1 [ffff800084a2f820] __schedule at ffff800040bfa0c4      #2 [ffff800084a2f880] schedule at ffff800040bfa4b4      #3 [ffff800084a2f8a0] io_schedule at ffff800040bfa9c4      #4 [ffff800084a2f8c0] rq_qos_wait at ffff8000405925bc      #5 [ffff800084a2f940] wbt_wait at ffff8000405bb3a0      #6 [ffff800084a2f9a0] __rq_qos_throttle at ffff800040592254      #7 [ffff800084a2f9c0] blk_mq_make_request at ffff80004057cf38      #8 [ffff800084a2fa60] generic_make_request at ffff800040570138      #9 [ffff800084a2fae0] submit_bio at ffff8000405703b4     #10 [ffff800084a2fb50] xlog_write_iclog at ffff800001280834 [xfs]     #11 [ffff800084a2fbb0] xlog_sync at ffff800001280c3c [xfs]     #12 [ffff800084a2fbf0] xlog_state_release_iclog at ffff800001280df4 [xfs]     #13 [ffff800084a2fc10] xlog_write at ffff80000128203c [xfs]     #14 [ffff800084a2fcd0] xlog_cil_push at ffff8000012846dc [xfs]     #15 [ffff800084a2fda0] xlog_cil_push_work at ffff800001284a2c [xfs]     #16 [ffff800084a2fdb0] process_one_work at ffff800040111d08     #17 [ffff800084a2fe00] worker_thread at ffff8000401121cc     #18 [ffff800084a2fe70] kthread at ffff800040118de4  After commit 2def2845cc33 (\"xfs: don't allow log IO to be throttled\"), the metadata submitted by xlog_write_iclog() should not be throttled. But due to the existence of the dm layer, throttling flush_bio indirectly causes the metadata bio to be throttled.  Fix this by conditionally adding REQ_IDLE to flush_bio.bi_opf, which makes wbt_should_throttle() return false to avoid wbt_wait().","modified":"2026-09-01T16:06:13.497397405Z","published":"2025-06-18T10:15:39.207Z","upstream":["CVE-2025-38063"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38063"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.147-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.140-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38063.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.32-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38063.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.32-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38063.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}