« Volver al listado

CVE-2026-90390

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

md/bitmap: resume array on backlog_store() error path

backlog_store() suspends the array before checking whether a write-mostly device exists. If no such device exists, the error path only unlocks reconfig_mutex and leaves the array suspended, blocking subsequent I/O.

Use mddev_unlock_and_resume() to release both states.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90390",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "58226942ad3d1423785f815ede5bcc832574f2ea",
              "lessThan": "03aad318f0a1f039dddf98739e705fdca3bf0d86",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "58226942ad3d1423785f815ede5bcc832574f2ea",
              "lessThan": "6763fb409a0b4106676a52cf934440d9484b32c8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "58226942ad3d1423785f815ede5bcc832574f2ea",
              "lessThan": "cc543e769b97d563b089b9e0ebf8ad361d15076f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "58226942ad3d1423785f815ede5bcc832574f2ea",
              "lessThan": "2911cd0a0f4366a7e06832bc5f0a7fdcc138e4dc",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/md/md-bitmap.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/md/md-bitmap.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:38.530",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/03aad318f0a1f039dddf98739e705fdca3bf0d86",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2911cd0a0f4366a7e06832bc5f0a7fdcc138e4dc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6763fb409a0b4106676a52cf934440d9484b32c8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cc543e769b97d563b089b9e0ebf8ad361d15076f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/bitmap: resume array on backlog_store() error path\n\nbacklog_store() suspends the array before checking whether a write-mostly\ndevice exists. If no such device exists, the error path only unlocks\nreconfig_mutex and leaves the array suspended, blocking subsequent I/O.\n\nUse mddev_unlock_and_resume() to release both states."
    }
  ],
  "lastModified": "2026-09-17T17:17:38.530",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}