CVE-2026-90279
In the Linux kernel, the following vulnerability has been resolved:
md/raid5: round bitmap stripes with sector division
raid5_bitmap_sector_map() aligns the array range to full RAID5 stripe widths before converting it to component sectors. That width is chunk_sectors multiplied by the number of data disks, and it is not always a power of two.
Reproduce with a 4-disk RAID5, 1024-sector chunks, and three data disks. The full-stripe width is 3072 sectors. For a one-sector write at array sector 3072, correct rounding gives array range [3072, 6144), which maps to component range [1024, 2048). The old round_down()/round_up() logic instead gives [1024, 4096), which maps to [0, 1024).
Leer descripción completaMostrar menos
Use sector_div() based arithmetic so the rounded range is aligned to the actual RAID5 stripe width.
The deterministic mapper test now reports the fixed component range as [1024, 2048), while the old mask-based range was [0, 1024).
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/02c10581866d08822c6348e299881485fc546185
- https://git.kernel.org/stable/c/17ea021ae74987d6064c8195c4922fa025753892
- https://git.kernel.org/stable/c/9d7490007707f90691911385365bd1d691d99225
- https://git.kernel.org/stable/c/cab7d949b18b2f1cd625689dc16c5f81236bac93
- https://git.kernel.org/stable/c/ccbdc483eb041eef809e9ff223d1ad63518a2c52
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90279",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "b29e6400be51c214a0ad30dce937348b57abe33a",
"lessThan": "9d7490007707f90691911385365bd1d691d99225",
"versionType": "git"
},
{
"status": "affected",
"version": "aa8e15d69f5c0044d5bff61844e163aacc4ac172",
"lessThan": "cab7d949b18b2f1cd625689dc16c5f81236bac93",
"versionType": "git"
},
{
"status": "affected",
"version": "9c89f604476cf15c31fbbdb043cff7fbf1dbe0cb",
"lessThan": "02c10581866d08822c6348e299881485fc546185",
"versionType": "git"
},
{
"status": "affected",
"version": "9c89f604476cf15c31fbbdb043cff7fbf1dbe0cb",
"lessThan": "ccbdc483eb041eef809e9ff223d1ad63518a2c52",
"versionType": "git"
},
{
"status": "affected",
"version": "9c89f604476cf15c31fbbdb043cff7fbf1dbe0cb",
"lessThan": "17ea021ae74987d6064c8195c4922fa025753892",
"versionType": "git"
},
{
"status": "affected",
"version": "a41a0df5d7638acf15e723ad985980b4f7ff9383",
"versionType": "git"
},
{
"status": "affected",
"version": "6.6.79",
"lessThan": "6.6.157",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.12.13",
"lessThan": "6.12.110",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.13.2",
"lessThan": "6.14",
"versionType": "semver"
}
],
"programFiles": [
"drivers/md/raid5.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.14"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.14",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/md/raid5.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:24.567",
"references": [
{
"url": "https://git.kernel.org/stable/c/02c10581866d08822c6348e299881485fc546185",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/17ea021ae74987d6064c8195c4922fa025753892",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9d7490007707f90691911385365bd1d691d99225",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cab7d949b18b2f1cd625689dc16c5f81236bac93",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ccbdc483eb041eef809e9ff223d1ad63518a2c52",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid5: round bitmap stripes with sector division\n\nraid5_bitmap_sector_map() aligns the array range to full RAID5 stripe\nwidths before converting it to component sectors. That width is\nchunk_sectors multiplied by the number of data disks, and it is not\nalways a power of two.\n\nReproduce with a 4-disk RAID5, 1024-sector chunks, and three data disks.\nThe full-stripe width is 3072 sectors. For a one-sector write at array\nsector 3072, correct rounding gives array range [3072, 6144), which maps\nto component range [1024, 2048). The old round_down()/round_up() logic\ninstead gives [1024, 4096), which maps to [0, 1024).\n\nUse sector_div() based arithmetic so the rounded range is aligned to the\nactual RAID5 stripe width.\n\nThe deterministic mapper test now reports the fixed component range as\n[1024, 2048), while the old mask-based range was [0, 1024)."
}
],
"lastModified": "2026-09-17T17:17:24.567",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}