Description
In the Linux kernel, the following vulnerability has been resolved:

md: wait for behind writes before destroying bitmap

__md_stop() destroyed the bitmap before calling mddev_detach(). That made
mddev_detach() skip bitmap_ops->wait_behind_writes(), because the bitmap
was already disconnected from mddev.

This was still safe for the legacy bitmap because bitmap_destroy() waits
for behind writes itself. llbitmap keeps that wait in its
->wait_behind_writes() operation instead, while ->destroy() tears down the
llbitmap storage. With the old ordering, RAID1 behind-write completions
could still run after llbitmap storage had been freed.

Call mddev_detach() before md_bitmap_destroy() so the common detach path
can wait for behind writes while the bitmap is still alive. Only destroy
the bitmap after those users are gone.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Data Corruption via Use‑After‑Free
Action: Patch Kernel
AI Analysis

Impact

A race condition in the Linux kernel’s RAID subsystem caused the bitmap to be destroyed before the detach routine waited for ongoing behind‑write operations to finish. When the bitmap is torn down while writes are still in flight, those writes can reference freed memory. This results in a use‑after‑free that can corrupt data or cause a kernel panic. The vulnerability is local to systems running affected kernel versions and does not provide network‑based exploitation paths.

Affected Systems

All Linux kernel releases prior to the patch applied in late 2026 are affected. The flaw is present in the generic ‘linux_kernel’ product regardless of distribution, as the revision is a core kernel change. No specific kernel version range is listed in the current data, so any system not yet updated to the fixed commit set is susceptible.

Risk and Exploitability

The EPSS score is reported as <1 %, indicating a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog, and no CVSS score is provided in the data. Exploitation requires an attacker to be able to initiate behind‑write operations on a RAID device while the bitmap is in the process of being torn down—conditions unlikely to be met without local privilege. Consequently, the risk is considered low to moderate, mainly affecting data integrity and system stability.

Generated by OpenCVE AI on September 19, 2026 at 04:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that moves the mddev_detach call before md_bitmap_destroy, such as integrating the commits 2a79365b, 4224dccd, and 73881ff into the kernel source and recompiling.
  • Reboot the system into the patched kernel or reload the updated RAID modules to ensure the clean bit ordering is in effect.
  • Verify that no active RAID arrays are performing simultaneous behind‑write operations during the upgrade; if possible, temporarily stop or pause affected RAID devices before applying the patch.

Generated by OpenCVE AI on September 19, 2026 at 04:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: md: wait for behind writes before destroying bitmap __md_stop() destroyed the bitmap before calling mddev_detach(). That made mddev_detach() skip bitmap_ops->wait_behind_writes(), because the bitmap was already disconnected from mddev. This was still safe for the legacy bitmap because bitmap_destroy() waits for behind writes itself. llbitmap keeps that wait in its ->wait_behind_writes() operation instead, while ->destroy() tears down the llbitmap storage. With the old ordering, RAID1 behind-write completions could still run after llbitmap storage had been freed. Call mddev_detach() before md_bitmap_destroy() so the common detach path can wait for behind writes while the bitmap is still alive. Only destroy the bitmap after those users are gone.
Title md: wait for behind writes before destroying bitmap
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:09.992Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90278

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:24.460

Modified: 2026-09-17T17:17:24.460

Link: CVE-2026-90278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T05:00:08Z

Weaknesses