CVE-2026-68449

Unknown

Last modified

CVE-2026-68449 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning The hand-rolled bit-scanning loop in the NCQ completion path has an infinite loop bug. When tag_mask has only high bits set (e.g. 0x80000000), the inner while loop left-shifts tag_mask until it overflows to 0.

Description

In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning The hand-rolled bit-scanning loop in the NCQ completion path has an infinite loop bug. When tag_mask has only high bits set (e.g. 0x80000000), the inner while loop left-shifts tag_mask until it overflows to 0. At that point !(0 & 1) is always true and 0 <<= 1 stays 0, causing an infinite loop in hardirq context with a spinlock held. Replace the open-coded bit-scanning with __ffs() which correctly finds the least significant set bit and is bounded by the width of the argument.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 62936009f35a6659cc3ebe0d90c754182d60da73, < 4c6e64cae2b2dab32ad9099faa339f6a72c0ce16; >= 62936009f35a6659cc3ebe0d90c754182d60da73, < 8c5de0d8ab6824cfdadcbbe1be4c6c9d9f4c1f80; >= 62936009f35a6659cc3ebe0d90c754182d60da73, < 1842d45f461a78988254631893329bdf4596e954; >= 62936009f35a6659cc3ebe0d90c754182d60da73, < 29b916d3556bd12a95be7c56ca391b8cd572f8be; >= 62936009f35a6659cc3ebe0d90c754182d60da73, < c2130f6553f4a5cbdc259de069600117a995f197
LinuxLinux2.6.36

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-68449?
In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning The hand-rolled bit-scanning loop in the NCQ completion path has an infinite loop bug. When tag_mask has only high bits set (e.g. 0x80000000), the inner while loop left-shifts tag_mask until it overflows to 0. At that point !(0 & 1) is always true and 0 <<= 1 stays 0, causing an infinite loop in hardirq context with a spinlock held. Replace the open-coded bit-scanning with __ffs() which correctly finds the least significant set bit and is bounded by the width of the argument.
How severe is CVE-2026-68449?
Severity scoring for CVE-2026-68449 is pending analysis.
How do I fix CVE-2026-68449?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-68449?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST