CVE-2026-45888 PUBLISHED

md/raid1: fix memory leak in raid1_run()

Assigner: Linux
Reserved: 13.05.2026 Published: 27.05.2026 Updated: 27.05.2026

In the Linux kernel, the following vulnerability has been resolved:

md/raid1: fix memory leak in raid1_run()

raid1_run() calls setup_conf() which registers a thread via md_register_thread(). If raid1_set_limits() fails, the previously registered thread is not unregistered, resulting in a memory leak of the md_thread structure and the thread resource itself.

Add md_unregister_thread() to the error path to properly cleanup the thread, which aligns with the error handling logic of other paths in this function.

Compile tested only. Issue found using a prototype static analysis tool and code review.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 97894f7d3c2966164516a8a5109674763d3a55e1 to c94fd6e8a71efd047ff36930e840f3c25679e136 (excl.)
  • affected from 97894f7d3c2966164516a8a5109674763d3a55e1 to ec10e3dc93994b87adf7c759a4639fe34013989a (excl.)
  • affected from 97894f7d3c2966164516a8a5109674763d3a55e1 to b37588b0282a2b3cdda9db1d53712745ce66dea0 (excl.)
  • affected from 97894f7d3c2966164516a8a5109674763d3a55e1 to 6abc7d5dcf0ee0f85e16e41c87fbd06231f28753 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.9 is affected
  • unaffected from 0 to 6.9 (excl.)
  • unaffected from 6.12.75 to 6.12.* (incl.)
  • unaffected from 6.18.14 to 6.18.* (incl.)
  • unaffected from 6.19.4 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References