{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.5.3-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.5.3-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  virtio_pmem: add the missing REQ_OP_WRITE for flush bio  When doing mkfs.xfs on a pmem device, the following warning was   ------------[ cut here ]------------  WARNING: CPU: 2 PID: 384 at block/blk-core.c:751 submit_bio_noacct  Modules linked in:  CPU: 2 PID: 384 Comm: mkfs.xfs Not tainted 6.4.0-rc7+ #154  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)  RIP: 0010:submit_bio_noacct+0x340/0x520  ......  Call Trace:   \u003cTASK\u003e   ? submit_bio_noacct+0xd5/0x520   submit_bio+0x37/0x60   async_pmem_flush+0x79/0xa0   nvdimm_flush+0x17/0x40   pmem_submit_bio+0x370/0x390   __submit_bio+0xbc/0x190   submit_bio_noacct_nocheck+0x14d/0x370   submit_bio_noacct+0x1ef/0x520   submit_bio+0x55/0x60   submit_bio_wait+0x5a/0xc0   blkdev_issue_flush+0x44/0x60  The root cause is that submit_bio_noacct() needs bio_op() is either WRITE or ZONE_APPEND for flush bio and async_pmem_flush() doesn't assign REQ_OP_WRITE when allocating flush bio, so submit_bio_noacct just fail the flush bio.  Simply fix it by adding the missing REQ_OP_WRITE for flush bio. And we could fix the flush order issue and do flush optimization later.",
  "id": "DEBIAN-CVE-2023-54089",
  "modified": "2026-09-01T19:48:36.631081861Z",
  "published": "2025-12-24T13:16:10.767Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2023-54089"
    }
  ],
  "upstream": [
    "CVE-2023-54089"
  ]
}