CVE-2026-90276
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
md/md-llbitmap: stop daemon timer rearm on destroy
llbitmap_destroy() deletes pending_timer before flushing md_llbitmap_io_wq. However, daemon_work can still be queued or running after the timer has been deleted, and the daemon path can arm pending_timer again when it finds dirty chunks that are not ready to flush yet.
If that happens during teardown, pending_timer can remain armed after llbitmap is freed and later dereference freed memory.
Add a BITMAP_SHUTDOWN bit to llbitmap->flags, set it before deleting the timer, and make the timer and daemon paths stop queueing or rearming work once teardown starts. Cancel daemon_work before flushing the shared workqueue so no already queued daemon instance can race with the free. Use timer_shutdown_sync() so a daemon instance that passed the shutdown check before teardown cannot rearm the timer afterward.
BITMAP_SHUTDOWN is a runtime-only state. Mask it out when reading and updating the llbitmap superblock so the shutdown state is never loaded from disk or persisted to disk.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 5ab829f1971dc99f2aac10846c378e67fc875abc < c55aa6c17f019b6296952d336939891efa084c06 | affected |
| Linux | Linux | 5ab829f1971dc99f2aac10846c378e67fc875abc < bb7f92d58fca9a9f06f3f51a82481c5f0bbbd46c | affected |
| Linux | Linux | 5ab829f1971dc99f2aac10846c378e67fc875abc < 5553d64e01d9a995be6c3de38501c6dd4ceede3b | affected |
| Linux | Linux | 6.18 | affected |
| Linux | Linux | 0 < 6.18 | unaffected |
| Linux | Linux | 6.18.52 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.6 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/c55aa6c17f019b6296952d336939891efa084c06
- https://git.kernel.org/stable/c/bb7f92d58fca9a9f06f3f51a82481c5f0bbbd46c
- https://git.kernel.org/stable/c/5553d64e01d9a995be6c3de38501c6dd4ceede3b
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.