{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93262","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.097Z","datePublished":"2026-09-24T15:52:01.886Z","dateUpdated":"2026-09-25T05:09:54.351Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-25T05:09:54.351Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid5-ppl: fix use-after-free in ppl_do_flush()\n\nThe loop in ppl_do_flush() continues iterating after calling\nppl_io_unit_finished(), touching io->pending_flushes and leading to a\nuse-after-free.\n\nAdd a break statement to stop the loop once io is freed."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The patched ppl_do_flush() runs from ppl_stripe_write_finished() after RAID5 stripe data+parity I/O completes. Those writes enter via md_submit_bio() -> raid5_make_request() from local write(2) to a filesystem or /dev/md*; ppl_submit_iounit() only sets disk_flush_bitmap from local stripe R5_Wantwrite/wb_cache_on state, not from a network protocol message.\nAC:L - Writes the attacker issues are logged by ppl_write_stripe()/ppl_log_stripe() and ppl_submit_iounit() sets disk_flush_bitmap for child_logs[i].wb_cache_on members. When pending_stripes hits 0, ppl_stripe_write_finished() calls ppl_do_flush(); the remainder loop's missing break after ppl_io_unit_finished() is a logic bug on that path, not a second-actor race or a disk-fault precondition.\nPR:L - md_submit_bio() and raid5_make_request() have no capability check; md_ioctl()'s capable(CAP_SYS_ADMIN) applies only to array-management ioctls, not I/O. An unprivileged user who can write a filesystem on the RAID5+PPL array (or /dev/md* with disk-group write access) reaches ppl_do_flush() without init-namespace root.\nUI:N - The attacker triggers ppl_do_flush() through their own writes: raid5 handle_stripe()/handle_stripe_clean_event() calls ppl_stripe_write_finished() on I/O they submitted. No victim action such as mounting an image or plugging a device is required.\nS:U - ppl_io_unit_finished() mempool_free()s the ppl_io_unit from ppl_conf->io_pool in the host md/raid5 kernel. The later dangling atomic_dec_and_test(&io->pending_flushes) in ppl_do_flush() stays in that kernel's authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - ppl_io_unit_finished() returns the ppl_io_unit to io_pool via mempool_free(); ppl_do_flush()'s remainder loop then does atomic_dec_and_test(&io->pending_flushes) on that freed kmem_cache object. A UAF of the recycled io_unit header is a kernel read primitive against adjacent/reconstituted pool memory.\nI:H - The same dangling io is a writeable ppl_io_unit: atomic_dec_and_test() mutates pending_flushes on a recycled object, and another true dec_and_test would call ppl_io_unit_finished() again (list_del/mempool_free of a live unit). That is a kernel write/double-free primitive on the PPL io_unit cache.\nA:H - Use-after-free of the mempool ppl_io_unit in ppl_do_flush() after ppl_io_unit_finished() can oops on the stale pending_flushes access or corrupt list_del() pointers in a second finish, panicking the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/md/raid5-ppl.c"],"versions":[{"version":"1532d9e87e8b2377f12929f9e40724d5fbe6ecc5","lessThan":"cf01f9413565e86673baf927291a088b6975692b","status":"affected","versionType":"git"},{"version":"1532d9e87e8b2377f12929f9e40724d5fbe6ecc5","lessThan":"e7505842f1329ece90cb9ea0db87772aeca44052","status":"affected","versionType":"git"},{"version":"1532d9e87e8b2377f12929f9e40724d5fbe6ecc5","lessThan":"b5123bf667ac29ddd8106f9ca7cc01316513ae66","status":"affected","versionType":"git"},{"version":"1532d9e87e8b2377f12929f9e40724d5fbe6ecc5","lessThan":"e77c80670f2c2bf491da9b173931e1da4677c23a","status":"affected","versionType":"git"},{"version":"1532d9e87e8b2377f12929f9e40724d5fbe6ecc5","lessThan":"8914c3d40870f16429a326e97e4016bedc6ede4c","status":"affected","versionType":"git"},{"version":"1532d9e87e8b2377f12929f9e40724d5fbe6ecc5","lessThan":"455b56209f9615c3902dcc398dd867abb5ade3ab","status":"affected","versionType":"git"},{"version":"1532d9e87e8b2377f12929f9e40724d5fbe6ecc5","lessThan":"fcf21df7d3c50c8ebeb0757df5d21b02dcae4218","status":"affected","versionType":"git"},{"version":"1532d9e87e8b2377f12929f9e40724d5fbe6ecc5","lessThan":"371f7a1b392edc8b7cf449cc7713179b588f2d0e","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/md/raid5-ppl.c"],"versions":[{"version":"4.16","status":"affected"},{"version":"0","lessThan":"4.16","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/cf01f9413565e86673baf927291a088b6975692b"},{"url":"https://git.kernel.org/stable/c/e7505842f1329ece90cb9ea0db87772aeca44052"},{"url":"https://git.kernel.org/stable/c/b5123bf667ac29ddd8106f9ca7cc01316513ae66"},{"url":"https://git.kernel.org/stable/c/e77c80670f2c2bf491da9b173931e1da4677c23a"},{"url":"https://git.kernel.org/stable/c/8914c3d40870f16429a326e97e4016bedc6ede4c"},{"url":"https://git.kernel.org/stable/c/455b56209f9615c3902dcc398dd867abb5ade3ab"},{"url":"https://git.kernel.org/stable/c/fcf21df7d3c50c8ebeb0757df5d21b02dcae4218"},{"url":"https://git.kernel.org/stable/c/371f7a1b392edc8b7cf449cc7713179b588f2d0e"}],"title":"md/raid5-ppl: fix use-after-free in ppl_do_flush()","x_generator":{"engine":"bippy-1.2.0"}}}}