Description
In the Linux kernel, the following vulnerability has been resolved:

md/bitmap: resume array on backlog_store() error path

backlog_store() suspends the array before checking whether a write-mostly
device exists. If no such device exists, the error path only unlocks
reconfig_mutex and leaves the array suspended, blocking subsequent I/O.

Use mddev_unlock_and_resume() to release both states.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service due to suspended array blocking I/O
Action: Patch Kernel
AI Analysis

Impact

In the Linux kernel, a flaw in backlog_store() suspends an array before verifying whether a write‑mostly device exists. If not, the error path unlocks only reconfig_mutex while leaving the array suspended, thereby preventing any further I/O on that device. The result is a local denial of service that can incapacitate problematic arrays and disrupt related workloads.

Affected Systems

All Linux kernel installations are potentially affected, as the vulnerability is present in the core MD subsystem. No specific kernel version range is listed, so all releases until the patch are at risk unless the kernel has already been updated to a fixed build.

Risk and Exploitability

The EPSS score is below 1 %, suggesting a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because it requires an attacker with sufficient local privileges to manipulate array configurations, the threat is considered moderate; however, the impact on service availability can be critical for environments that rely heavily on software‑RAID arrays.

Generated by OpenCVE AI on September 19, 2026 at 05:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that contains the backlog_store() error‑path fix
  • Reboot the system after updating the kernel to ensure any suspended arrays are fully released
  • Monitor kernel logs for messages related to array suspension or I/O failures and confirm that arrays resume normally after the update

Generated by OpenCVE AI on September 19, 2026 at 05:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-673

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: md/bitmap: resume array on backlog_store() error path backlog_store() suspends the array before checking whether a write-mostly device exists. If no such device exists, the error path only unlocks reconfig_mutex and leaves the array suspended, blocking subsequent I/O. Use mddev_unlock_and_resume() to release both states.
Title md/bitmap: resume array on backlog_store() error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:24.405Z

Reserved: 2026-09-11T19:38:34.810Z

Link: CVE-2026-90390

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:38.530

Modified: 2026-09-17T17:17:38.530

Link: CVE-2026-90390

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T07:00:10Z

Weaknesses
  • CWE-673

    External Influence of Sphere Definition