dm: fix NULL pointer dereference in __dm_suspend()
Published Nov 12, 2025
4.7
MEDIUMCVSS 3.1
EPSS 0.21%
Description
There is a race condition between dm device suspend and table load that can lead to null pointer dereference. The issue occurs when suspend is invoked before table load completes:
BUG: kernel NULL pointer dereference, address: 0000000000000054 Oops: 0000 [#1] PREEMPT SMP PTI CPU: 6 PID: 6798 Comm: dmsetup Not tainted 6.6.0-g7e52f5f0ca9b #62 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.1-2.fc37 04/01/2014 RIP: 0010:blk_mq_wait_quiesce_done+0x0/0x50 Call Trace: <TASK> blk_mq_quiesce_queue+0x2c/0x50 dm_stop_queue+0xd/0x20 __dm_suspend+0x130/0x330 dm_suspend+0x11a/0x180 dev_suspend+0x27e/0x560 ctl_ioctl+0x4cf/0x850 dm_ctl_ioctl+0xd/0x20 vfs_ioctl+0x1d/0x50 __se_sys_ioctl+0x9b/0xc0 __x64_sys_ioctl+0x19/0x30 x64_sys_call+0x2c4a/0x4620 do_syscall_64+0x9e/0x1b0
The issue can be triggered as below:
T1 T2 dm_suspend table_load __dm_suspend dm_setup_md_queue dm_mq_init_request_queue blk_mq_init_allocated_queue => q->mq_ops = set->ops; (1) dm_stop_queue / dm_wait_for_completion => q->tag_set NULL pointer! (2) => q->tag_set = set; (3)
Fix this by checking if a valid table (map) exists before performing request-based suspend and waiting for target I/O. When map is NULL, skip these table-dependent suspend steps.
Even when map is NULL, no I/O can reach any target because there is no table loaded; I/O submitted in this state will fail early in the DM layer. Skipping the table-dependent suspend logic in this case is safe and avoids NULL pointer dereferences.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.0StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.0
- Version 5.10.246StatusunaffectedConstraints<=5.10.*
- Version 5.15.195StatusunaffectedConstraints<=5.15.*
- Version 5.4.301StatusunaffectedConstraints<=5.4.*
- Version 6.1.156StatusunaffectedConstraints<=6.1.*
- Version 6.12.53StatusunaffectedConstraints<=6.12.*
- Version 6.17.3StatusunaffectedConstraints<=6.17.*
- Version 6.18StatusunaffectedConstraints<=*
- Version 6.6.112StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel-0:6.12.0-211.7.1.el10_2
Fixed · RHSA-2026:18134
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.5.1.el9_8
Fixed · RHSA-2026:18587
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.5.1.el9_8
Fixed · RHSA-2026:18587
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel-0:6.12.0-211.7.1.el10_2 | Fixed | RHSA-2026:18134 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.5.1.el9_8 | Fixed | RHSA-2026:18587 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.5.1.el9_8 | Fixed | RHSA-2026:18587 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.21% (0.00212) | 10.35th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.18% (0.00184) | 8.06th | v5 (v2026.06.15) |
| Nov 12, 2025 | 0.02% (0.00024) | 5.44th | v4 (v2025.03.14) |
References (13)
- https://access.redhat.com/security/cve/CVE-2025-40134 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2414468 Issue Tracking
- https://git.kernel.org/stable/c/19ca4528666990be376ac3eb6fe667b03db5324d
- https://git.kernel.org/stable/c/30f95b7eda5966b81cb221bd569c0f095a068cf6
- https://git.kernel.org/stable/c/331c2dd8ca8bad1a3ac10cce847ffb76158eece4
- https://git.kernel.org/stable/c/846cafc4725ca727d94f9c4b5f789c1a7c8fb6fe
- https://git.kernel.org/stable/c/8d33a030c566e1f105cd5bf27f37940b6367f3be
- https://git.kernel.org/stable/c/9dc43ea6a20ff83fe9a5fe4be47ae0fbf2409b98
- https://git.kernel.org/stable/c/a0e54bd8d7ea79127fe9920df3ae36f85e79ac7c
- https://git.kernel.org/stable/c/a802901b75e13cc306f1b7ab0f062135c8034e9e
- https://lore.kernel.org/linux-cve-announce/2025111254-CVE-2025-40134-4d24@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-40134
- https://www.cve.org/CVERecord?id=CVE-2025-40134
Change history (0)
No recorded changes yet.