Description
In the Linux kernel, the following vulnerability has been resolved:

md: recheck spare changes before starting sync

remove_spares() and remove_and_add_spares() modify the array's rdev
configuration. These operations are only safe after the array has been
suspended.

md_start_sync() checks whether spare configuration changes are needed
before taking reconfig_mutex. However, the rdev state can change before
the mutex is acquired, so the initial check can become stale. In that
case, md_choose_sync_action() may remove or replace rdevs while normal
I/O is still accessing them.

The race can occur as follows:

raid10d Worker Normal IO
____________ _______________________ ______________________

raid10_write_request()
wait_blocked_dev()
set Blocked
set Faulty
Skip Faulty rdev
rrdev->nr_pending++
.repl_bio = bio
removeable_rdev = false .
array not suspended .
lock mddev goto err_handle
lock mddev (wait)
.
update sb .
clear Blocked .
.
unlock mddev .
lock mddev (acquires)
remove_spares()
removeable_rdev = true

raid10_remove_disk()
rdev = replacement
replacement = NULL
rdev_dec_pending(NULL)
unlock mddev (NULL)->nr_pending--

In this case, rdev_dec_pending() is called with a NULL pointer,
resulting in a NULL pointer dereference when attempting to decrement
nr_pending.

Fix this by suspending the array when spare configuration changes are
needed, including for non-read-write arrays, and checking again after
taking reconfig_mutex. If the array was not already suspended and a
change is now needed, release the mutex, suspend the array, and
reacquire the mutex before continuing.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash due to NULL pointer dereference, resulting in denial of service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a race between array suspension and spare configuration changes in the Linux kernel’s md subsystem, causing the kernel to dereference a NULL pointer during the removal of a disk. This can crash the kernel, producing a system halt or requiring a reboot. The flaw is a classic race condition that leads to a NULL pointer dereference and therefore can abort all user processes and affect system availability. It does not directly expose data but can be leveraged as a denial‑of‑service vector by repeatedly inducing the race condition.

Affected Systems

All Linux systems that run a kernel containing the unpatched md build. No specific kernel release numbers are disclosed, but any kernel that includes the md_start_sync and remove_spares logic is potentially susceptible. System administrators should inspect the kernel version and verify whether it contains the fixed logic or has received an update incorporating the patch. Hackers who can trigger heavier I/O load on RAID arrays might augment the race to reliably cause a crash.

Risk and Exploitability

EPSS indicates a very low exploitation probability of less than 1 %. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The bug manifests as a local kernel race; an attacker would need to generate concurrent I/O on the RAID array to trigger the race, making it more of a reliability issue than an easily exploitable security flaw. Nonetheless, the severity of a kernel crash in a production environment is high enough to merit prompt action.

Generated by OpenCVE AI on September 19, 2026 at 14:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the upstream kernel patch or install a vendor update that includes the race‑condition fix.
  • If an update is not yet available, suspend the RAID array during maintenance windows to prevent spare configuration changes while I/O is active.
  • Monitor kernel logs for OOPS or BUG messages and block any operations that could trigger the race until the patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 14:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-368
CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: md: recheck spare changes before starting sync remove_spares() and remove_and_add_spares() modify the array's rdev configuration. These operations are only safe after the array has been suspended. md_start_sync() checks whether spare configuration changes are needed before taking reconfig_mutex. However, the rdev state can change before the mutex is acquired, so the initial check can become stale. In that case, md_choose_sync_action() may remove or replace rdevs while normal I/O is still accessing them. The race can occur as follows: raid10d Worker Normal IO ____________ _______________________ ______________________ raid10_write_request() wait_blocked_dev() set Blocked set Faulty Skip Faulty rdev rrdev->nr_pending++ .repl_bio = bio removeable_rdev = false . array not suspended . lock mddev goto err_handle lock mddev (wait) . update sb . clear Blocked . . unlock mddev . lock mddev (acquires) remove_spares() removeable_rdev = true raid10_remove_disk() rdev = replacement replacement = NULL rdev_dec_pending(NULL) unlock mddev (NULL)->nr_pending-- In this case, rdev_dec_pending() is called with a NULL pointer, resulting in a NULL pointer dereference when attempting to decrement nr_pending. Fix this by suspending the array when spare configuration changes are needed, including for non-read-write arrays, and checking again after taking reconfig_mutex. If the array was not already suspended and a change is now needed, release the mutex, suspend the array, and reacquire the mutex before continuing.
Title md: recheck spare changes before starting sync
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:30.915Z

Reserved: 2026-09-11T19:38:34.811Z

Link: CVE-2026-90400

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:39.753

Modified: 2026-09-17T17:17:39.753

Link: CVE-2026-90400

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:30:07Z

Weaknesses
  • CWE-368

    Context Switching Race Condition

  • CWE-476

    NULL Pointer Dereference