Impact
The vulnerability allows a race between array suspension and spare configuration changes in the Linux kernel’s md subsystem, causing the kernel to dereference a NULL pointer during the removal of a disk. This can crash the kernel, producing a system halt or requiring a reboot. The flaw is a classic race condition that leads to a NULL pointer dereference and therefore can abort all user processes and affect system availability. It does not directly expose data but can be leveraged as a denial‑of‑service vector by repeatedly inducing the race condition.
Affected Systems
All Linux systems that run a kernel containing the unpatched md build. No specific kernel release numbers are disclosed, but any kernel that includes the md_start_sync and remove_spares logic is potentially susceptible. System administrators should inspect the kernel version and verify whether it contains the fixed logic or has received an update incorporating the patch. Hackers who can trigger heavier I/O load on RAID arrays might augment the race to reliably cause a crash.
Risk and Exploitability
EPSS indicates a very low exploitation probability of less than 1 %. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The bug manifests as a local kernel race; an attacker would need to generate concurrent I/O on the RAID array to trigger the race, making it more of a reliability issue than an easily exploitable security flaw. Nonetheless, the severity of a kernel crash in a production environment is high enough to merit prompt action.
OpenCVE Enrichment
Debian DLA
Debian DSA