CVE-2026-68449 PUBLISHED

ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning

Assigner: Linux
Reserved: 30.07.2026 Published: 12.08.2026 Updated: 12.08.2026

In the Linux kernel, the following vulnerability has been resolved:

ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning

The hand-rolled bit-scanning loop in the NCQ completion path has an infinite loop bug. When tag_mask has only high bits set (e.g. 0x80000000), the inner while loop left-shifts tag_mask until it overflows to 0. At that point !(0 & 1) is always true and 0 <<= 1 stays 0, causing an infinite loop in hardirq context with a spinlock held.

Replace the open-coded bit-scanning with __ffs() which correctly finds the least significant set bit and is bounded by the width of the argument.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 62936009f35a6659cc3ebe0d90c754182d60da73 to 4c6e64cae2b2dab32ad9099faa339f6a72c0ce16 (excl.)
  • affected from 62936009f35a6659cc3ebe0d90c754182d60da73 to 8c5de0d8ab6824cfdadcbbe1be4c6c9d9f4c1f80 (excl.)
  • affected from 62936009f35a6659cc3ebe0d90c754182d60da73 to 1842d45f461a78988254631893329bdf4596e954 (excl.)
  • affected from 62936009f35a6659cc3ebe0d90c754182d60da73 to 29b916d3556bd12a95be7c56ca391b8cd572f8be (excl.)
  • affected from 62936009f35a6659cc3ebe0d90c754182d60da73 to c2130f6553f4a5cbdc259de069600117a995f197 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.36 is affected
  • unaffected from 0 to 2.6.36 (excl.)
  • unaffected from 6.6.148 to 6.6.* (incl.)
  • unaffected from 6.12.101 to 6.12.* (incl.)
  • unaffected from 6.18.42 to 6.18.* (incl.)
  • unaffected from 7.1.6 to 7.1.* (incl.)
  • unaffected from 7.2-rc4 to * (incl.)

References