๐Ÿ” CVE Alert

CVE-2026-90400

UNKNOWN 0.0

md: recheck spare changes before starting sync

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: md: recheck spare changes before starting sync remove_spares() and remove_and_add_spares() modify the array's rdev configuration. These operations are only safe after the array has been suspended. md_start_sync() checks whether spare configuration changes are needed before taking reconfig_mutex. However, the rdev state can change before the mutex is acquired, so the initial check can become stale. In that case, md_choose_sync_action() may remove or replace rdevs while normal I/O is still accessing them. The race can occur as follows: raid10d Worker Normal IO ____________ _______________________ ______________________ raid10_write_request() wait_blocked_dev() set Blocked set Faulty Skip Faulty rdev rrdev->nr_pending++ .repl_bio = bio removeable_rdev = false . array not suspended . lock mddev goto err_handle lock mddev (wait) . update sb . clear Blocked . . unlock mddev . lock mddev (acquires) remove_spares() removeable_rdev = true raid10_remove_disk() rdev = replacement replacement = NULL rdev_dec_pending(NULL) unlock mddev (NULL)->nr_pending-- In this case, rdev_dec_pending() is called with a NULL pointer, resulting in a NULL pointer dereference when attempting to decrement nr_pending. Fix this by suspending the array when spare configuration changes are needed, including for non-read-write arrays, and checking again after taking reconfig_mutex. If the array was not already suspended and a change is now needed, release the mutex, suspend the array, and reacquire the mutex before continuing.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
bc08041b32abe6c9824f78735bac22018eabfc06 < c3777d16bc3335c0ac4bdad0551c80d38c5d94cc bc08041b32abe6c9824f78735bac22018eabfc06 < e5ac7ab78467b064f1da8b0f3042a63595fafcfd bc08041b32abe6c9824f78735bac22018eabfc06 < 81b39df5d701976cf20e52f33106c1fc1603b4cb bc08041b32abe6c9824f78735bac22018eabfc06 < c7d34d17ea43ebc86b45d439ebb435e11ca44bca
Linux / Linux
6.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c3777d16bc3335c0ac4bdad0551c80d38c5d94cc git.kernel.org: https://git.kernel.org/stable/c/e5ac7ab78467b064f1da8b0f3042a63595fafcfd git.kernel.org: https://git.kernel.org/stable/c/81b39df5d701976cf20e52f33106c1fc1603b4cb git.kernel.org: https://git.kernel.org/stable/c/c7d34d17ea43ebc86b45d439ebb435e11ca44bca