-

CVE-2026-90279

md/raid5: round bitmap stripes with sector division

In the Linux kernel, the following vulnerability has been resolved:

md/raid5: round bitmap stripes with sector division

raid5_bitmap_sector_map() aligns the array range to full RAID5 stripe
widths before converting it to component sectors. That width is
chunk_sectors multiplied by the number of data disks, and it is not
always a power of two.

Reproduce with a 4-disk RAID5, 1024-sector chunks, and three data disks.
The full-stripe width is 3072 sectors. For a one-sector write at array
sector 3072, correct rounding gives array range [3072, 6144), which maps
to component range [1024, 2048). The old round_down()/round_up() logic
instead gives [1024, 4096), which maps to [0, 1024).

Use sector_div() based arithmetic so the rounded range is aligned to the
actual RAID5 stripe width.

The deterministic mapper test now reports the fixed component range as
[1024, 2048), while the old mask-based range was [0, 1024).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b29e6400be51c214a0ad30dce937348b57abe33a
Version < 9d7490007707f90691911385365bd1d691d99225
Status affected
Version aa8e15d69f5c0044d5bff61844e163aacc4ac172
Version < cab7d949b18b2f1cd625689dc16c5f81236bac93
Status affected
Version 9c89f604476cf15c31fbbdb043cff7fbf1dbe0cb
Version < 02c10581866d08822c6348e299881485fc546185
Status affected
Version 9c89f604476cf15c31fbbdb043cff7fbf1dbe0cb
Version < ccbdc483eb041eef809e9ff223d1ad63518a2c52
Status affected
Version 9c89f604476cf15c31fbbdb043cff7fbf1dbe0cb
Version < 17ea021ae74987d6064c8195c4922fa025753892
Status affected
Version a41a0df5d7638acf15e723ad985980b4f7ff9383
Status affected
Version 6.6.79
Version < 6.6.157
Status affected
Version 6.12.13
Version < 6.12.110
Status affected
Version 6.13.2
Version < 6.14
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.14
Status affected
Version 0
Version < 6.14
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9d7490007707f90691911385365bd1d691d99225
https://git.kernel.org/stable/c/cab7d949b18b2f1cd625689dc16c5f81236bac93
https://git.kernel.org/stable/c/02c10581866d08822c6348e299881485fc546185
https://git.kernel.org/stable/c/ccbdc483eb041eef809e9ff223d1ad63518a2c52
https://git.kernel.org/stable/c/17ea021ae74987d6064c8195c4922fa025753892