« Volver al listado

CVE-2026-90400

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

md: recheck spare changes before starting sync

remove_spares() and remove_and_add_spares() modify the array's rdev configuration. These operations are only safe after the array has been suspended.

md_start_sync() checks whether spare configuration changes are needed before taking reconfig_mutex. However, the rdev state can change before the mutex is acquired, so the initial check can become stale. In that case, md_choose_sync_action() may remove or replace rdevs while normal I/O is still accessing them.

The race can occur as follows:

Leer descripción completaMostrar menos

raid10d Worker Normal IO ____________ _______________________ ______________________

In this case, rdev_dec_pending() is called with a NULL pointer, resulting in a NULL pointer dereference when attempting to decrement nr_pending.

Fix this by suspending the array when spare configuration changes are needed, including for non-read-write arrays, and checking again after taking reconfig_mutex. If the array was not already suspended and a change is now needed, release the mutex, suspend the array, and reacquire the mutex before continuing.

Detalles técnicos trazas, registros y código del informe original
                                             raid10_write_request()
                                             wait_blocked_dev()
set Blocked
set Faulty
                                             Skip Faulty rdev
                                             rrdev->nr_pending++
                                             .repl_bio = bio
                 removeable_rdev = false     .
                 array not suspended         .
lock mddev                                   goto err_handle
                 lock mddev (wait)
                 .
update sb        .
clear Blocked    .
                 .
unlock mddev     .
                 lock mddev (acquires)
                 remove_spares()
                 removeable_rdev = true

                 raid10_remove_disk()
                 rdev = replacement
                 replacement = NULL
                                             rdev_dec_pending(NULL)
                 unlock mddev                (NULL)->nr_pending--

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90400",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "bc08041b32abe6c9824f78735bac22018eabfc06",
              "lessThan": "c3777d16bc3335c0ac4bdad0551c80d38c5d94cc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bc08041b32abe6c9824f78735bac22018eabfc06",
              "lessThan": "e5ac7ab78467b064f1da8b0f3042a63595fafcfd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bc08041b32abe6c9824f78735bac22018eabfc06",
              "lessThan": "81b39df5d701976cf20e52f33106c1fc1603b4cb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bc08041b32abe6c9824f78735bac22018eabfc06",
              "lessThan": "c7d34d17ea43ebc86b45d439ebb435e11ca44bca",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/md/md.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/md/md.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:39.753",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/81b39df5d701976cf20e52f33106c1fc1603b4cb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c3777d16bc3335c0ac4bdad0551c80d38c5d94cc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c7d34d17ea43ebc86b45d439ebb435e11ca44bca",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e5ac7ab78467b064f1da8b0f3042a63595fafcfd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd: recheck spare changes before starting sync\n\nremove_spares() and remove_and_add_spares() modify the array's rdev\nconfiguration. These operations are only safe after the array has been\nsuspended.\n\nmd_start_sync() checks whether spare configuration changes are needed\nbefore taking reconfig_mutex. However, the rdev state can change before\nthe mutex is acquired, so the initial check can become stale. In that\ncase, md_choose_sync_action() may remove or replace rdevs while normal\nI/O is still accessing them.\n\nThe race can occur as follows:\n\nraid10d          Worker                      Normal IO\n____________     _______________________     ______________________\n\n                                             raid10_write_request()\n                                             wait_blocked_dev()\nset Blocked\nset Faulty\n                                             Skip Faulty rdev\n                                             rrdev->nr_pending++\n                                             .repl_bio = bio\n                 removeable_rdev = false     .\n                 array not suspended         .\nlock mddev                                   goto err_handle\n                 lock mddev (wait)\n                 .\nupdate sb        .\nclear Blocked    .\n                 .\nunlock mddev     .\n                 lock mddev (acquires)\n                 remove_spares()\n                 removeable_rdev = true\n\n                 raid10_remove_disk()\n                 rdev = replacement\n                 replacement = NULL\n                                             rdev_dec_pending(NULL)\n                 unlock mddev                (NULL)->nr_pending--\n\nIn this case, rdev_dec_pending() is called with a NULL pointer,\nresulting in a NULL pointer dereference when attempting to decrement\nnr_pending.\n\nFix this by suspending the array when spare configuration changes are\nneeded, including for non-read-write arrays, and checking again after\ntaking reconfig_mutex. If the array was not already suspended and a\nchange is now needed, release the mutex, suspend the array, and\nreacquire the mutex before continuing."
    }
  ],
  "lastModified": "2026-09-17T17:17:39.753",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}