« Volver al listado

CVE-2026-90385

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

md/raid1: create serial pool adding rdev to array with serialize_policy=1

The following bug has been observed with kernel 7.1.3 after adding a new rdev to an existing RAID1 array with serialize_policy enabled:

The raid1.c code calls wait_for_serialization() if the MD_SERIALIZE_POLICY is set, and wait_for_serialization assumes that rdev->serial is initialized. Normally this will be the case for arrays that have the serialize_policy sysfs attribute set to 1.

But when a new rdev is added to an existing array in bind_rdev_to_array(), the condition at mddev_create_serial_pool() causes creation of rdev->serial to be skipped. Fix it.

Detalles técnicos trazas, registros y código del informe original
  Oops: 0002 [#1]
  CPU: 0 UID: 0 PID: 19639 Comm: ext4lazyinit Not tainted 7.1.3-1-default
  RIP: _raw_spin_lock_irqsave+0x27/0x50
  CR2: 0000000000004960
  Call Trace:
   wait_for_serialization+0xb9/0x260 [raid1]
   raid1_make_request+0x762/0xaff [raid1]
   md_handle_request+0x1c9/0x2e0 [md_mod]

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90385",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "69b00b5bb23552d43e8bbed73ef6624604bb94a2",
              "lessThan": "f9e4364449f7ca6917f3599eb32064dba5b7b147",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "69b00b5bb23552d43e8bbed73ef6624604bb94a2",
              "lessThan": "37f11973c3eb72a5eb061082cad529bb6939c24f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "69b00b5bb23552d43e8bbed73ef6624604bb94a2",
              "lessThan": "c02d675e81468003e4f2253b616c53729070d712",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "69b00b5bb23552d43e8bbed73ef6624604bb94a2",
              "lessThan": "140234b2380ffb8ffb0cfc46fee0e822f43adef7",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/md/md.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/md/md.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:37.880",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/140234b2380ffb8ffb0cfc46fee0e822f43adef7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/37f11973c3eb72a5eb061082cad529bb6939c24f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c02d675e81468003e4f2253b616c53729070d712",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f9e4364449f7ca6917f3599eb32064dba5b7b147",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid1: create serial pool adding rdev to array with serialize_policy=1\n\nThe following bug has been observed with kernel 7.1.3 after adding a new\nrdev to an existing RAID1 array with serialize_policy enabled:\n\n  Oops: 0002 [#1]\n  CPU: 0 UID: 0 PID: 19639 Comm: ext4lazyinit Not tainted 7.1.3-1-default\n  RIP: _raw_spin_lock_irqsave+0x27/0x50\n  CR2: 0000000000004960\n  Call Trace:\n   wait_for_serialization+0xb9/0x260 [raid1]\n   raid1_make_request+0x762/0xaff [raid1]\n   md_handle_request+0x1c9/0x2e0 [md_mod]\n\nThe raid1.c code calls wait_for_serialization() if the MD_SERIALIZE_POLICY\nis set, and wait_for_serialization assumes that rdev->serial is\ninitialized. Normally this will be the case for arrays that have\nthe serialize_policy sysfs attribute set to 1.\n\nBut when a new rdev is added to an existing array in bind_rdev_to_array(),\nthe condition at mddev_create_serial_pool() causes creation of rdev->serial\nto be skipped. Fix it."
    }
  ],
  "lastModified": "2026-09-17T17:17:37.880",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}