CVE-2026-90400
In the Linux kernel, the following vulnerability has been resolved:
md: recheck spare changes before starting sync
remove_spares() and remove_and_add_spares() modify the array's rdev configuration. These operations are only safe after the array has been suspended.
md_start_sync() checks whether spare configuration changes are needed before taking reconfig_mutex. However, the rdev state can change before the mutex is acquired, so the initial check can become stale. In that case, md_choose_sync_action() may remove or replace rdevs while normal I/O is still accessing them.
The race can occur as follows:
Leer descripción completaMostrar menos
raid10d Worker Normal IO ____________ _______________________ ______________________
In this case, rdev_dec_pending() is called with a NULL pointer, resulting in a NULL pointer dereference when attempting to decrement nr_pending.
Fix this by suspending the array when spare configuration changes are needed, including for non-read-write arrays, and checking again after taking reconfig_mutex. If the array was not already suspended and a change is now needed, release the mutex, suspend the array, and reacquire the mutex before continuing.
Detalles técnicos trazas, registros y código del informe original
raid10_write_request()
wait_blocked_dev()
set Blocked
set Faulty
Skip Faulty rdev
rrdev->nr_pending++
.repl_bio = bio
removeable_rdev = false .
array not suspended .
lock mddev goto err_handle
lock mddev (wait)
.
update sb .
clear Blocked .
.
unlock mddev .
lock mddev (acquires)
remove_spares()
removeable_rdev = true
raid10_remove_disk()
rdev = replacement
replacement = NULL
rdev_dec_pending(NULL)
unlock mddev (NULL)->nr_pending--CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90400",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "bc08041b32abe6c9824f78735bac22018eabfc06",
"lessThan": "c3777d16bc3335c0ac4bdad0551c80d38c5d94cc",
"versionType": "git"
},
{
"status": "affected",
"version": "bc08041b32abe6c9824f78735bac22018eabfc06",
"lessThan": "e5ac7ab78467b064f1da8b0f3042a63595fafcfd",
"versionType": "git"
},
{
"status": "affected",
"version": "bc08041b32abe6c9824f78735bac22018eabfc06",
"lessThan": "81b39df5d701976cf20e52f33106c1fc1603b4cb",
"versionType": "git"
},
{
"status": "affected",
"version": "bc08041b32abe6c9824f78735bac22018eabfc06",
"lessThan": "c7d34d17ea43ebc86b45d439ebb435e11ca44bca",
"versionType": "git"
}
],
"programFiles": [
"drivers/md/md.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/md/md.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:39.753",
"references": [
{
"url": "https://git.kernel.org/stable/c/81b39df5d701976cf20e52f33106c1fc1603b4cb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c3777d16bc3335c0ac4bdad0551c80d38c5d94cc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c7d34d17ea43ebc86b45d439ebb435e11ca44bca",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e5ac7ab78467b064f1da8b0f3042a63595fafcfd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd: recheck spare changes before starting sync\n\nremove_spares() and remove_and_add_spares() modify the array's rdev\nconfiguration. These operations are only safe after the array has been\nsuspended.\n\nmd_start_sync() checks whether spare configuration changes are needed\nbefore taking reconfig_mutex. However, the rdev state can change before\nthe mutex is acquired, so the initial check can become stale. In that\ncase, md_choose_sync_action() may remove or replace rdevs while normal\nI/O is still accessing them.\n\nThe race can occur as follows:\n\nraid10d Worker Normal IO\n____________ _______________________ ______________________\n\n raid10_write_request()\n wait_blocked_dev()\nset Blocked\nset Faulty\n Skip Faulty rdev\n rrdev->nr_pending++\n .repl_bio = bio\n removeable_rdev = false .\n array not suspended .\nlock mddev goto err_handle\n lock mddev (wait)\n .\nupdate sb .\nclear Blocked .\n .\nunlock mddev .\n lock mddev (acquires)\n remove_spares()\n removeable_rdev = true\n\n raid10_remove_disk()\n rdev = replacement\n replacement = NULL\n rdev_dec_pending(NULL)\n unlock mddev (NULL)->nr_pending--\n\nIn this case, rdev_dec_pending() is called with a NULL pointer,\nresulting in a NULL pointer dereference when attempting to decrement\nnr_pending.\n\nFix this by suspending the array when spare configuration changes are\nneeded, including for non-read-write arrays, and checking again after\ntaking reconfig_mutex. If the array was not already suspended and a\nchange is now needed, release the mutex, suspend the array, and\nreacquire the mutex before continuing."
}
],
"lastModified": "2026-09-17T17:17:39.753",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}