-

CVE-2026-90389

md: scope memalloc_noio to allocation critical sections

In the Linux kernel, the following vulnerability has been resolved:

md: scope memalloc_noio to allocation critical sections

Storing a memalloc_noio_save() token in mddev->noio_flags lets one task
save the token and another task restore it. With concurrent suspend sysfs
writes, task A can enter PF_MEMALLOC_NOIO, return to userspace still in
that scope, and later task B can restore A's saved token.

Avoid tying the token lifetime to mddev. Keep mddev_suspend() and
mddev_resume() only responsible for array suspension, and enter
PF_MEMALLOC_NOIO only in the MD paths that allocate memory after the array
has been suspended. Restore the token before resuming the array.

A reproducer repeatedly writes suspend_lo and suspend_hi from concurrent
workers and checks each worker's /proc/self/stat flags before and after the
sysfs write.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 78f57ef9d50a75326da73d352d7c27828495229a
Version < 72ebfdf507ede7d7f2b7ca0a5634811a0e4bf045
Status affected
Version 78f57ef9d50a75326da73d352d7c27828495229a
Version < 28fdea874f68cac6c36651b1fc7272fd2199c48d
Status affected
Version 78f57ef9d50a75326da73d352d7c27828495229a
Version < a58923756b0f8e71032070c23ae0b167e46731da
Status affected
Version 78f57ef9d50a75326da73d352d7c27828495229a
Version < bace2010dd7ac07bc980575afb135c406730a7fe
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.8
Status affected
Version 0
Version < 5.8
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/72ebfdf507ede7d7f2b7ca0a5634811a0e4bf045
https://git.kernel.org/stable/c/28fdea874f68cac6c36651b1fc7272fd2199c48d
https://git.kernel.org/stable/c/a58923756b0f8e71032070c23ae0b167e46731da
https://git.kernel.org/stable/c/bace2010dd7ac07bc980575afb135c406730a7fe