CVE-2026-90400
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
md: recheck spare changes before starting sync
remove_spares() and remove_and_add_spares() modify the array's rdev configuration. These operations are only safe after the array has been suspended.
md_start_sync() checks whether spare configuration changes are needed before taking reconfig_mutex. However, the rdev state can change before the mutex is acquired, so the initial check can become stale. In that case, md_choose_sync_action() may remove or replace rdevs while normal I/O is still accessing them.
The race can occur as follows:
raid10d Worker Normal IO
raid10_write_request()
wait_blocked_dev()
set Blocked set Faulty Skip Faulty rdev rrdev->nr_pending++ .repl_bio = bio removeable_rdev = false . array not suspended . lock mddev goto err_handle lock mddev (wait) . update sb . clear Blocked . . unlock mddev . lock mddev (acquires) remove_spares() removeable_rdev = true
raid10_remove_disk()
rdev = replacement
replacement = NULL
rdev_dec_pending(NULL)
unlock mddev (NULL)->nr_pending--
In this case, rdev_dec_pending() is called with a NULL pointer, resulting in a NULL pointer dereference when attempting to decrement nr_pending.
Fix this by suspending the array when spare configuration changes are needed, including for non-read-write arrays, and checking again after taking reconfig_mutex. If the array was not already suspended and a change is now needed, release the mutex, suspend the array, and reacquire the mutex before continuing.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | bc08041b32abe6c9824f78735bac22018eabfc06 < c3777d16bc3335c0ac4bdad0551c80d38c5d94cc | affected |
| Linux | Linux | bc08041b32abe6c9824f78735bac22018eabfc06 < e5ac7ab78467b064f1da8b0f3042a63595fafcfd | affected |
| Linux | Linux | bc08041b32abe6c9824f78735bac22018eabfc06 < 81b39df5d701976cf20e52f33106c1fc1603b4cb | affected |
| Linux | Linux | bc08041b32abe6c9824f78735bac22018eabfc06 < c7d34d17ea43ebc86b45d439ebb435e11ca44bca | affected |
| Linux | Linux | 6.7 | affected |
| Linux | Linux | 0 < 6.7 | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.52 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.6 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/c3777d16bc3335c0ac4bdad0551c80d38c5d94cc
- https://git.kernel.org/stable/c/e5ac7ab78467b064f1da8b0f3042a63595fafcfd
- https://git.kernel.org/stable/c/81b39df5d701976cf20e52f33106c1fc1603b4cb
- https://git.kernel.org/stable/c/c7d34d17ea43ebc86b45d439ebb435e11ca44bca
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.