{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90400","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.811Z","datePublished":"2026-09-17T16:09:30.915Z","dateUpdated":"2026-09-17T16:09:30.915Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-17T16:09:30.915Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd: recheck spare changes before starting sync\n\nremove_spares() and remove_and_add_spares() modify the array's rdev\nconfiguration. These operations are only safe after the array has been\nsuspended.\n\nmd_start_sync() checks whether spare configuration changes are needed\nbefore taking reconfig_mutex. However, the rdev state can change before\nthe mutex is acquired, so the initial check can become stale. In that\ncase, md_choose_sync_action() may remove or replace rdevs while normal\nI/O is still accessing them.\n\nThe race can occur as follows:\n\nraid10d          Worker                      Normal IO\n____________     _______________________     ______________________\n\n                                             raid10_write_request()\n                                             wait_blocked_dev()\nset Blocked\nset Faulty\n                                             Skip Faulty rdev\n                                             rrdev->nr_pending++\n                                             .repl_bio = bio\n                 removeable_rdev = false     .\n                 array not suspended         .\nlock mddev                                   goto err_handle\n                 lock mddev (wait)\n                 .\nupdate sb        .\nclear Blocked    .\n                 .\nunlock mddev     .\n                 lock mddev (acquires)\n                 remove_spares()\n                 removeable_rdev = true\n\n                 raid10_remove_disk()\n                 rdev = replacement\n                 replacement = NULL\n                                             rdev_dec_pending(NULL)\n                 unlock mddev                (NULL)->nr_pending--\n\nIn this case, rdev_dec_pending() is called with a NULL pointer,\nresulting in a NULL pointer dereference when attempting to decrement\nnr_pending.\n\nFix this by suspending the array when spare configuration changes are\nneeded, including for non-read-write arrays, and checking again after\ntaking reconfig_mutex. If the array was not already suspended and a\nchange is now needed, release the mutex, suspend the array, and\nreacquire the mutex before continuing."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/md/md.c"],"versions":[{"version":"bc08041b32abe6c9824f78735bac22018eabfc06","lessThan":"c3777d16bc3335c0ac4bdad0551c80d38c5d94cc","status":"affected","versionType":"git"},{"version":"bc08041b32abe6c9824f78735bac22018eabfc06","lessThan":"e5ac7ab78467b064f1da8b0f3042a63595fafcfd","status":"affected","versionType":"git"},{"version":"bc08041b32abe6c9824f78735bac22018eabfc06","lessThan":"81b39df5d701976cf20e52f33106c1fc1603b4cb","status":"affected","versionType":"git"},{"version":"bc08041b32abe6c9824f78735bac22018eabfc06","lessThan":"c7d34d17ea43ebc86b45d439ebb435e11ca44bca","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/md/md.c"],"versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/c3777d16bc3335c0ac4bdad0551c80d38c5d94cc"},{"url":"https://git.kernel.org/stable/c/e5ac7ab78467b064f1da8b0f3042a63595fafcfd"},{"url":"https://git.kernel.org/stable/c/81b39df5d701976cf20e52f33106c1fc1603b4cb"},{"url":"https://git.kernel.org/stable/c/c7d34d17ea43ebc86b45d439ebb435e11ca44bca"}],"title":"md: recheck spare changes before starting sync","x_generator":{"engine":"bippy-1.2.0"}}}}