CVE-2026-90400

Summary

In the Linux kernel, the following vulnerability has been resolved:

md: recheck spare changes before starting sync

remove_spares() and remove_and_add_spares() modify the array's rdev configuration. These operations are only safe after the array has been suspended.

md_start_sync() checks whether spare configuration changes are needed before taking reconfig_mutex. However, the rdev state can change before the mutex is acquired, so the initial check can become stale. In that case, md_choose_sync_action() may remove or replace rdevs while normal I/O is still accessing them.

The race can occur as follows:

raid10d Worker Normal IO


                                         raid10_write_request()
                                         wait_blocked_dev()

set Blocked set Faulty Skip Faulty rdev rrdev->nr_pending++ .repl_bio = bio removeable_rdev = false . array not suspended . lock mddev goto err_handle lock mddev (wait) . update sb . clear Blocked . . unlock mddev . lock mddev (acquires) remove_spares() removeable_rdev = true

             raid10_remove_disk()
             rdev = replacement
             replacement = NULL
                                         rdev_dec_pending(NULL)
             unlock mddev                (NULL)->nr_pending--

In this case, rdev_dec_pending() is called with a NULL pointer, resulting in a NULL pointer dereference when attempting to decrement nr_pending.

Fix this by suspending the array when spare configuration changes are needed, including for non-read-write arrays, and checking again after taking reconfig_mutex. If the array was not already suspended and a change is now needed, release the mutex, suspend the array, and reacquire the mutex before continuing.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxbc08041b32abe6c9824f78735bac22018eabfc06 < c3777d16bc3335c0ac4bdad0551c80d38c5d94ccaffected
LinuxLinuxbc08041b32abe6c9824f78735bac22018eabfc06 < e5ac7ab78467b064f1da8b0f3042a63595fafcfdaffected
LinuxLinuxbc08041b32abe6c9824f78735bac22018eabfc06 < 81b39df5d701976cf20e52f33106c1fc1603b4cbaffected
LinuxLinuxbc08041b32abe6c9824f78735bac22018eabfc06 < c7d34d17ea43ebc86b45d439ebb435e11ca44bcaaffected
LinuxLinux6.7affected
LinuxLinux0 < 6.7unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References