Description
In the Linux kernel, the following vulnerability has been resolved:

md/md-llbitmap: prevent create failure bitmap UAF

llbitmap_create() publishes mddev->bitmap before reading the bitmap
superblock. This is needed because llbitmap_read_sb() can initialize a
new bitmap and flush it through helpers that use mddev->bitmap.

If llbitmap_read_sb() fails, the old cleanup dropped bitmap_info.mutex
and freed llbitmap before clearing mddev->bitmap. Readers such as
/proc/mdstat rely on bitmap_info.mutex to keep the bitmap pointer stable
while collecting bitmap stats, so they could observe the stale pointer
after the failed create path released the mutex.

Clear mddev->bitmap while still holding bitmap_info.mutex, then free the
failed llbitmap after dropping the mutex. This makes mutex-protected
readers see either a live bitmap or no bitmap.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free may enable local denial of service or memory corruption
Action: Patch
AI Analysis

Impact

This vulnerability occurs in the Linux kernel’s llbitmap subsystem. During the creation of a bitmap, the code publishes a pointer to mddev->bitmap before successfully reading the bitmap superblock. If reading fails, the cleanup path drops the bitmap mutex, frees the llbitmap object, and leaves the mddev->bitmap pointer dangling. Readers that rely on this pointer, such as /proc/mdstat, may then observe a stale pointer while holding the mutex, leading to a use‑after‑free. This flaw can potentially expose memory contents or crash the system, resulting in a denial‑of‑service or, if the attacker controls the memory region, arbitrary code execution. The weakness is a classic use‑after‑free (CWE‑416).

Affected Systems

Affected systems are any Linux kernels that include the llbitmap code before the commit that introduced the fix. The issue is present across all mainstream Linux distributions that ship the kernel versions containing the unpatched llbitmap module. No specific vendor or product name beyond "Linux kernel" is listed in the vendor/product data.

Risk and Exploitability

The exploit probability is very low with an EPSS score of less than 1%, and it is not listed in the CISA KEV catalog, suggesting limited exploitation activity. However, the commit that fixed the issue is available on the official kernel Git tree, and the CVSS score is not listed, but the use‑after‑free indicates a notable severity. Attackers would need kernel or root access and a failure condition within llbitmap_read_sb(). The risk is primarily a local denial‑of‑service, though a crafted environment could lead to memory corruption or code execution if memory is overwritten after the use‑after‑free. The likely attack vector is local and requires kernel privileges.

Generated by OpenCVE AI on September 19, 2026 at 04:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the llbitmap cleanup fix, which is available in commit 2116c2f0a0e547615886900e2ed8c529c016499b.
  • Reboot the system after updating so that the new kernel module is loaded.
  • Verify that /proc/mdstat no longer reports stale bitmap pointers and monitor system logs for any related errors.

Generated by OpenCVE AI on September 19, 2026 at 04:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: prevent create failure bitmap UAF llbitmap_create() publishes mddev->bitmap before reading the bitmap superblock. This is needed because llbitmap_read_sb() can initialize a new bitmap and flush it through helpers that use mddev->bitmap. If llbitmap_read_sb() fails, the old cleanup dropped bitmap_info.mutex and freed llbitmap before clearing mddev->bitmap. Readers such as /proc/mdstat rely on bitmap_info.mutex to keep the bitmap pointer stable while collecting bitmap stats, so they could observe the stale pointer after the failed create path released the mutex. Clear mddev->bitmap while still holding bitmap_info.mutex, then free the failed llbitmap after dropping the mutex. This makes mutex-protected readers see either a live bitmap or no bitmap.
Title md/md-llbitmap: prevent create failure bitmap UAF
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:09.328Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90277

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:24.353

Modified: 2026-09-17T17:17:24.353

Link: CVE-2026-90277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T04:30:16Z

Weaknesses