Description
In the Linux kernel, the following vulnerability has been resolved:

md/raid5: round bitmap stripes with sector division

raid5_bitmap_sector_map() aligns the array range to full RAID5 stripe
widths before converting it to component sectors. That width is
chunk_sectors multiplied by the number of data disks, and it is not
always a power of two.

Reproduce with a 4-disk RAID5, 1024-sector chunks, and three data disks.
The full-stripe width is 3072 sectors. For a one-sector write at array
sector 3072, correct rounding gives array range [3072, 6144), which maps
to component range [1024, 2048). The old round_down()/round_up() logic
instead gives [1024, 4096), which maps to [0, 1024).

Use sector_div() based arithmetic so the rounded range is aligned to the
actual RAID5 stripe width.

The deterministic mapper test now reports the fixed component range as
[1024, 2048), while the old mask-based range was [0, 1024).
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Data integrity compromise
Action: Patch
AI Analysis

Impact

The vulnerability is a logic flaw in the Linux kernel’s RAID5 bitmap mapping routine, where sector ranges are rounded according to an incorrect stripe width calculation. This misalignment can cause write and read operations to target the wrong component disks, leading to corruption or loss of stored data. The bug originates from the use of integer division that fails to account for non‑power‑of‑two stripe widths, a flaw that can be classified under CWE‑680 (Integer Overflow or Wraparound) and CWE‑682 (Incorrect Calculation).

Affected Systems

All Linux kernel releases that implement the described raid5_bitmap_sector_map logic before the commit that corrects the rounding behavior are affected. The exact kernel version impacted is not specified in the provided data; any system running an unpatched kernel containing the flawed code is vulnerable.

Risk and Exploitability

The EPSS score is less than 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires local access with the ability to perform I/O on a RAID5 array, so it is an intrinsic local privilege scenario. Reliability of attacks is limited by the lack of publicly available exploitation code and the narrow requirements for the target, so the overall risk is low but should be mitigated promptly.

Generated by OpenCVE AI on September 20, 2026 at 01:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that incorporates the round_bitmap_stripes fix for RAID5 to ensure the correct rounding logic is in effect.
  • Reboot the system after the kernel upgrade so that the updated code takes effect during boot.
  • If an immediate kernel upgrade is infeasible, suspend or remove the vulnerable RAID5 array, or migrate the data to a different storage configuration that does not use the buggy bitmap logic until the patch can be applied.

Generated by OpenCVE AI on September 20, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-680
CWE-682

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: md/raid5: round bitmap stripes with sector division raid5_bitmap_sector_map() aligns the array range to full RAID5 stripe widths before converting it to component sectors. That width is chunk_sectors multiplied by the number of data disks, and it is not always a power of two. Reproduce with a 4-disk RAID5, 1024-sector chunks, and three data disks. The full-stripe width is 3072 sectors. For a one-sector write at array sector 3072, correct rounding gives array range [3072, 6144), which maps to component range [1024, 2048). The old round_down()/round_up() logic instead gives [1024, 4096), which maps to [0, 1024). Use sector_div() based arithmetic so the rounded range is aligned to the actual RAID5 stripe width. The deterministic mapper test now reports the fixed component range as [1024, 2048), while the old mask-based range was [0, 1024).
Title md/raid5: round bitmap stripes with sector division
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:10.654Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90279

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:24.567

Modified: 2026-09-17T17:17:24.567

Link: CVE-2026-90279

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:30:16Z

Weaknesses
  • CWE-680

    Integer Overflow to Buffer Overflow

  • CWE-682

    Incorrect Calculation