Impact
The vulnerability lies in the Linux kernel's raid1_takeover() function, where the array_frozen flag is set to 1 on a newly allocated r1conf and never cleared. Earlier code would clear this flag via mddev_resume, but a recent commit removed that cleanup, causing any I/O to the affected RAID1 array to stall permanently. The result is a denial of service for the entire storage system because all read and write operations cease until the kernel is rebooted or the flag is manually reset.
Affected Systems
This defect affects all Linux kernel releases that include the commit that removed the quiesce call from mddev_suspend and subsequently introduced the buggy raid1_takeover logic. In practice, any system running a kernel version that contains these changes—typically kernel releases after the commit b39f35ebe86d—could be impacted. The exact range of affected kernel releases should be confirmed against the commit history for a specific environment.
Risk and Exploitability
The EPSS score is less than 1%, indicating a very low yet non‑zero exploitation probability. The vulnerability is not listed in CISA KEV. Exploitation requires the ability to perform a raid1 takeover, a privileged operation normally restricted to system administrators or automated management tools. Once executed, the attack will lock all I/O to the array, leading to persistent downtime until a reboot or manual reset is performed. Therefore the risk is primarily driven by the operational impact of a complete storage outage and the limited attack surface of privileged users.
OpenCVE Enrichment
Debian DLA
Debian DSA