Description
In the Linux kernel, the following vulnerability has been resolved:

md: scope memalloc_noio to allocation critical sections

Storing a memalloc_noio_save() token in mddev->noio_flags lets one task
save the token and another task restore it. With concurrent suspend sysfs
writes, task A can enter PF_MEMALLOC_NOIO, return to userspace still in
that scope, and later task B can restore A's saved token.

Avoid tying the token lifetime to mddev. Keep mddev_suspend() and
mddev_resume() only responsible for array suspension, and enter
PF_MEMALLOC_NOIO only in the MD paths that allocate memory after the array
has been suspended. Restore the token before resuming the array.

A reproducer repeatedly writes suspend_lo and suspend_hi from concurrent
workers and checks each worker's /proc/self/stat flags before and after the
sysfs write.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Privileged data corruption via race condition in kernel suspend handling
Action: Apply Patch
AI Analysis

Impact

This bug allows two separate userspace tasks to exchange a memalloc_noio token during kernel suspend/resume operations. By writing to the suspend sysfs entries concurrently, a task can enter the PF_MEMALLOC_NOIO state, return to userspace while still holding the token, and later another task can restore that same token, effectively hijacking the allocation guard. The result is that memory is allocated or de‑allocated under incorrect assumptions about the device’s state, potentially leading to data corruption or elevated privileges for the attacker. The weak point is a classic race condition, as the token’s lifetime is incorrectly tied to the device instead of the operation that set it.

Affected Systems

The vulnerability exists in all Linux kernel builds that contain the original memalloc_noio handling code before the commits that introduced the quick‑fix described in the advisory links. Versions of the kernel that have not incorporated the changes identified by the git commits 28fdea874f68..., 72ebfdf507e..., a58923756b0..., and bace2010dd7... are affected. In practice, every stable or mainline kernel released before the patch set is at risk until the kernel is updated to include the fixes.

Risk and Exploitability

The EPSS score is reported as less than 1%, indicating a low probability of public exploitation, and the vulnerability is not listed in CISA’s KEV catalog. No CVSS score is available in the published data, so the exact severity is unknown. The attack appears to require local privilege and concurrency between tasks that write to the MD suspend sysfs paths. While the described race could cause system instability or subtle corruption, it presents a potential for privilege escalation if the attacker can force the kernel to allocate memory with an incorrect flag. Given the low EPSS and lack of a public exploit, the risk is moderate but non‑negligible, and the issue should be remediated promptly.

Generated by OpenCVE AI on September 19, 2026 at 05:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the commits referenced in the advisory (for example, a kernel built from the source that incorporates the changes in commits 28fdea874f68, 72ebfdf507e, a58923756b0, and bace2010dd7).
  • If a kernel upgrade is not immediately possible, serialize accesses to the /sys/module/md/suspend_lo and suspend_hi sysfs entries so that only one process writes to them at a time; scripting an exclusive lock can mitigate the race condition.
  • Restrict write permissions on the MD suspend sysfs entries to privileged users or administrators to reduce the attack surface, and audit any suspicious concurrent writes to those files.

Generated by OpenCVE AI on September 19, 2026 at 05:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: md: scope memalloc_noio to allocation critical sections Storing a memalloc_noio_save() token in mddev->noio_flags lets one task save the token and another task restore it. With concurrent suspend sysfs writes, task A can enter PF_MEMALLOC_NOIO, return to userspace still in that scope, and later task B can restore A's saved token. Avoid tying the token lifetime to mddev. Keep mddev_suspend() and mddev_resume() only responsible for array suspension, and enter PF_MEMALLOC_NOIO only in the MD paths that allocate memory after the array has been suspended. Restore the token before resuming the array. A reproducer repeatedly writes suspend_lo and suspend_hi from concurrent workers and checks each worker's /proc/self/stat flags before and after the sysfs write.
Title md: scope memalloc_noio to allocation critical sections
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:23.767Z

Reserved: 2026-09-11T19:38:34.810Z

Link: CVE-2026-90389

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:38.427

Modified: 2026-09-17T17:17:38.427

Link: CVE-2026-90389

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T07:00:10Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')