---
id: CVE-2025-21807
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  block: fix queue freeze vs limits lock order in sysfs store methods

  queue_attr_store() always freezes a device queue before calling the
  attribute store operation
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  block: fix queue freeze vs limits lock order in sysfs store methods

  queue_attr_store() always freezes a device queue before calling the
  attribute store operation. For …
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-667
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.9, < 6.13.2'
patched:
  - linux_kernel 6.13.2
published: '2025-02-27'
updated: '2026-07-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-21807'
references:
  - url: 'https://git.kernel.org/stable/c/1645cd7fd42c236c952e9228badcac4fea1829ea'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8985da5481562e96b95e94ed8e5cc9b6565eb82b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c99f66e4084a62a2cc401c4704a84328aeddc9ec'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.0015
epssPercentile: 0.03447
ingestedAt: '2026-07-18T16:23:45.707Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

block: fix queue freeze vs limits lock order in sysfs store methods

queue_attr_store() always freezes a device queue before calling the
attribute store operation. For attributes that control queue limits, the
store operation will also lock the queue limits with a call to
queue_limits_start_update(). However, some drivers (e.g. SCSI sd) may
need to issue commands to a device to obtain limit values from the
hardware with the queue limits locked. This creates a potential ABBA
deadlock situation if a user attempts to modify a limit (thus freezing
the device queue) while the device driver starts a revalidation of the
device queue limits.

Avoid such deadlock by not freezing the queue before calling the
->store_limit() method in struct queue_sysfs_entry and instead use the
queue_limits_commit_update_frozen helper to freeze the queue after taking
the limits lock.

This also removes taking the sysfs lock for the store_limit method as
it doesn't protect anything here, but creates even more nesting.
Hopefully it will go away from the actual sysfs methods entirely soon.

(commit log adapted from a similar patch from  Damien Le Moal)

## Affected

- `linux_kernel >= 6.9, < 6.13.2`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.13.2`
