Description
In the Linux kernel, the following vulnerability has been resolved:

md/md-llbitmap: stop daemon timer rearm on destroy

llbitmap_destroy() deletes pending_timer before flushing
md_llbitmap_io_wq. However, daemon_work can still be queued or running
after the timer has been deleted, and the daemon path can arm
pending_timer again when it finds dirty chunks that are not ready to
flush yet.

If that happens during teardown, pending_timer can remain armed after
llbitmap is freed and later dereference freed memory.

Add a BITMAP_SHUTDOWN bit to llbitmap->flags, set it before deleting
the timer, and make the timer and daemon paths stop queueing or rearming
work once teardown starts. Cancel daemon_work before flushing the shared
workqueue so no already queued daemon instance can race with the free.
Use timer_shutdown_sync() so a daemon instance that passed the shutdown
check before teardown cannot rearm the timer afterward.

BITMAP_SHUTDOWN is a runtime-only state. Mask it out when reading and
updating the llbitmap superblock so the shutdown state is never loaded
from disk or persisted to disk.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free leading to kernel memory corruption that can crash the system or allow privilege escalation
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel’s block‑layer memory bitmap (md/md‑llbitmap) a timer that cleans dirty chunks may be rearmed after it has already been deleted during teardown. The daemon work can still be queued or still be running, so the timer can be armed again with a pointer to memory that has already been freed. This use‑after‑free can corrupt kernel memory, potentially causing a crash or providing an attacker with code execution in kernel mode.

Affected Systems

The flaw applies to the Linux kernel across all distributions that include the md/md‑llbitmap subsystem; vendor or version restrictions were not supplied, so every Linux kernel installation that uses this subsystem is potentially vulnerable until the patch is deployed.

Risk and Exploitability

The EPSS score is reported as less than 1 % and the weakness is not listed in the CISA KEV catalog, suggesting that active exploitation is very low at the time of this analysis. However, because the flaw occurs in privileged kernel code, a local attacker with the capability to trigger the teardown path or manipulate block devices can exploit the use‑after‑free to crash the kernel or elevate privileges. The attack vector is inferred to be local, requiring legitimate kernel access or the creation of a block device. Given the severity of kernel memory corruption, the risk remains high until the fix is applied.

Generated by OpenCVE AI on September 19, 2026 at 14:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that contains commit 5553d64e01d9a995be6c3de38501c6dd4ceede3b or later, ensuring the md/md‑llbitmap patch is included.
  • Reboot the system to load the updated kernel and clear any pending timers that may still reference freed memory.
  • If your environment builds a custom kernel, rebuild it with the patch applied and test the changes in a staging environment before deploying to production.

Generated by OpenCVE AI on September 19, 2026 at 14:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: stop daemon timer rearm on destroy llbitmap_destroy() deletes pending_timer before flushing md_llbitmap_io_wq. However, daemon_work can still be queued or running after the timer has been deleted, and the daemon path can arm pending_timer again when it finds dirty chunks that are not ready to flush yet. If that happens during teardown, pending_timer can remain armed after llbitmap is freed and later dereference freed memory. Add a BITMAP_SHUTDOWN bit to llbitmap->flags, set it before deleting the timer, and make the timer and daemon paths stop queueing or rearming work once teardown starts. Cancel daemon_work before flushing the shared workqueue so no already queued daemon instance can race with the free. Use timer_shutdown_sync() so a daemon instance that passed the shutdown check before teardown cannot rearm the timer afterward. BITMAP_SHUTDOWN is a runtime-only state. Mask it out when reading and updating the llbitmap superblock so the shutdown state is never loaded from disk or persisted to disk.
Title md/md-llbitmap: stop daemon timer rearm on destroy
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:08.697Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90276

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:24.247

Modified: 2026-09-17T17:17:24.247

Link: CVE-2026-90276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:00:12Z

Weaknesses