{"id":"CVE-2026-64003","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues\n\nWhile a SCSI host is in a recovery state, scsi_mq_requeue_cmd() will not\nset the requeue …","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues\n\nWhile a SCSI host is in a recovery state, scsi_mq_requeue_cmd() will not\nset the requeue …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-772"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 6.5, < 6.6.143","linux_kernel >= 6.7, < 6.12.93","linux_kernel >= 6.13, < 6.18.35","linux_kernel >= 6.19, < 7.0.12","linux_kernel = 7.1"],"patched":["linux_kernel 7.0.12"],"published":"2026-07-19","updated":"2026-10-08","sourceUpdated":"2026-10-08T18:30:24.653","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-64003","references":[{"url":"https://git.kernel.org/stable/c/15fb19af49f2073ed77fad16aaabc648b0ca6800","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/475f2b37a78f4c698967a7f14f325f04e24c9175","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7205b58702273baf21d6ba7992e6ba15852325f7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c740e13e7fe32d8e4d9a1699f65b8daf6709895a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4dddfecdbb5467bef158d4e1486459808357fef","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd"],"epss":0.00441,"epssPercentile":0.36238,"ingestedAt":"2026-10-08T18:58:11.293Z","slug":"CVE-2026-64003","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues\n\nWhile a SCSI host is in a recovery state, scsi_mq_requeue_cmd() will not\nset the requeue list for a requeued command to be kicked in the future.\nThe expectation is a call to scsi_run_host_queues() will kick all SCSI\ndevices once the recovery state is cleared.\n\nHowever, scsi_run_host_queues() uses shost_for_each_device() which uses\nscsi_device_get() and so will ignore devices in a partially removed\nstate like SDEV_CANCEL. But these devices may also have requeued\nrequests, leaving their requests stuck from not being kicked and causing\nthe removal process of the device to hang.\n\nscsi_run_host_queues() needs to run against more devices than the macro\nshost_for_each_device() allows. Instead of using the too limiting\nscsi_device_get() state checks, only ignore devices in SDEV_DEL state or\nwhen unable to acquire a reference. Attempt to run the queues for all\nother devices when scsi_run_host_queues() is called.\n\n## Affected\n\n- `linux_kernel >= 6.5, < 6.6.143`\n- `linux_kernel >= 6.7, < 6.12.93`\n- `linux_kernel >= 6.13, < 6.18.35`\n- `linux_kernel >= 6.19, < 7.0.12`\n- `linux_kernel = 7.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 7.0.12`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}