CVE-2023-54089
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-54089 is a Linux kernel vulnerability in the virtio_pmem subsystem caused by a missing REQ_OP_WRITE flag in flush bio operations on persistent memory (pmem) devices. The flaw was publicly disclosed on December 24, 2025, and affects Linux kernel versions from commit b4a6bb3a67aa0c37b2b6cd47efc326eb455de674 up to the patched releases in stable branches 6.4.16, 6.5.3, and 6.6. It was assigned a CVSS v3.1 base score of 7.0 (High) with a local attack vector and low privilege requirement (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is an omission in async_pmem_flush() within the virtio_pmem driver: when allocating a flush bio, the function fails to set the REQ_OP_WRITE operation flag. The submit_bio_noacct() function enforces that flush bio operations must have bio_op() set to either WRITE or ZONE_APPEND; without this flag, the flush bio is rejected, triggering a kernel WARN_ON at block/blk-core.c:751. This manifests as a kernel warning during operations like mkfs.xfs on a virtio pmem device in a QEMU virtualized environment. The issue is classified under improper handling of I/O operations (related to CWE-754: Improper Check for Unusual or Exceptional Conditions). The fix adds the missing REQ_OP_WRITE flag in the bio allocation within async_pmem_flush() (Red Hat Bugzilla, Feedly).

Impact

Exploitation of this vulnerability can cause I/O flush operations to fail silently or with kernel warnings on systems using virtio_pmem persistent memory devices, potentially leading to data integrity issues and system instability during write-flush cycles. The failure of flush bio operations may result in data not being properly committed to persistent storage, risking data loss or corruption. The scope is limited to systems running affected Linux kernel versions with virtio_pmem devices (typically QEMU/KVM virtualized environments), and there is no known path to remote code execution or lateral movement (Red Hat Advisory, Feedly).

Mitigation and workarounds

The fix has been applied to Linux kernel stable branches: version 6.4.16, 6.5.3, and 6.6 (and later). Administrators should update to the latest stable kernel version that includes the patch commits e39e870e1e683a71d3d2e63e661a5695f60931a7, c7ab7e45ccef209809f8c2b00f497deec06b29c0, or c1dbd8a849183b9c12d257ad3043ecec50db50b3 depending on their branch. Vendor-specific patches (e.g., SUSE kernel updates) are also available. Systems not using virtio_pmem persistent memory devices are not affected and require no action (Red Hat Bugzilla, Feedly).

Community reactions

Red Hat tracked the issue via Bugzilla and assigned it medium severity, with the upstream advisory published via the Linux kernel CVE announcement mailing list (lore.kernel.org). SUSE issued a kernel security advisory (SUSE-2026-0281-1) addressing this and related CVEs. No significant broader community or social media discussion has been observed beyond standard kernel security tracking channels (Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management