-
CVE-2026-90400
- EPSS 0.17%
- Veröffentlicht 17.09.2026 16:09:30
- Zuletzt bearbeitet 17.09.2026 17:17:39
- Erkennungen
md: recheck spare changes before starting sync
In the Linux kernel, the following vulnerability has been resolved:
md: recheck spare changes before starting sync
remove_spares() and remove_and_add_spares() modify the array's rdev
configuration. These operations are only safe after the array has been
suspended.
md_start_sync() checks whether spare configuration changes are needed
before taking reconfig_mutex. However, the rdev state can change before
the mutex is acquired, so the initial check can become stale. In that
case, md_choose_sync_action() may remove or replace rdevs while normal
I/O is still accessing them.
The race can occur as follows:
raid10d Worker Normal IO
____________ _______________________ ______________________
raid10_write_request()
wait_blocked_dev()
set Blocked
set Faulty
Skip Faulty rdev
rrdev->nr_pending++
.repl_bio = bio
removeable_rdev = false .
array not suspended .
lock mddev goto err_handle
lock mddev (wait)
.
update sb .
clear Blocked .
.
unlock mddev .
lock mddev (acquires)
remove_spares()
removeable_rdev = true
raid10_remove_disk()
rdev = replacement
replacement = NULL
rdev_dec_pending(NULL)
unlock mddev (NULL)->nr_pending--
In this case, rdev_dec_pending() is called with a NULL pointer,
resulting in a NULL pointer dereference when attempting to decrement
nr_pending.
Fix this by suspending the array when spare configuration changes are
needed, including for non-read-write arrays, and checking again after
taking reconfig_mutex. If the array was not already suspended and a
change is now needed, release the mutex, suspend the array, and
reacquire the mutex before continuing.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
bc08041b32abe6c9824f78735bac22018eabfc06
Version <
c3777d16bc3335c0ac4bdad0551c80d38c5d94cc
Status
affected
Version
bc08041b32abe6c9824f78735bac22018eabfc06
Version <
e5ac7ab78467b064f1da8b0f3042a63595fafcfd
Status
affected
Version
bc08041b32abe6c9824f78735bac22018eabfc06
Version <
81b39df5d701976cf20e52f33106c1fc1603b4cb
Status
affected
Version
bc08041b32abe6c9824f78735bac22018eabfc06
Version <
c7d34d17ea43ebc86b45d439ebb435e11ca44bca
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.7
Status
affected
Version
0
Version <
6.7
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.52
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.065 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/c3777d16bc3335c0ac4bdad0551c80d38c5d94cc
https://git.kernel.org/stable/c/e5ac7ab78467b064f1da8b0f3042a63595fafcfd
https://git.kernel.org/stable/c/81b39df5d701976cf20e52f33106c1fc1603b4cb
https://git.kernel.org/stable/c/c7d34d17ea43ebc86b45d439ebb435e11ca44bca