Impact
In the Linux kernel, a flaw in backlog_store() suspends an array before verifying whether a write‑mostly device exists. If not, the error path unlocks only reconfig_mutex while leaving the array suspended, thereby preventing any further I/O on that device. The result is a local denial of service that can incapacitate problematic arrays and disrupt related workloads.
Affected Systems
All Linux kernel installations are potentially affected, as the vulnerability is present in the core MD subsystem. No specific kernel version range is listed, so all releases until the patch are at risk unless the kernel has already been updated to a fixed build.
Risk and Exploitability
The EPSS score is below 1 %, suggesting a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because it requires an attacker with sufficient local privileges to manipulate array configurations, the threat is considered moderate; however, the impact on service availability can be critical for environments that rely heavily on software‑RAID arrays.
OpenCVE Enrichment
Debian DLA
Debian DSA