CVE-2026-90278 PUBLISHED

md: wait for behind writes before destroying bitmap

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

md: wait for behind writes before destroying bitmap

__md_stop() destroyed the bitmap before calling mddev_detach(). That made mddev_detach() skip bitmap_ops->wait_behind_writes(), because the bitmap was already disconnected from mddev.

This was still safe for the legacy bitmap because bitmap_destroy() waits for behind writes itself. llbitmap keeps that wait in its ->wait_behind_writes() operation instead, while ->destroy() tears down the llbitmap storage. With the old ordering, RAID1 behind-write completions could still run after llbitmap storage had been freed.

Call mddev_detach() before md_bitmap_destroy() so the common detach path can wait for behind writes while the bitmap is still alive. Only destroy the bitmap after those users are gone.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 5ab829f1971dc99f2aac10846c378e67fc875abc to 73881ff7a75913f919a1ce9d9571bfaab8e8588d (excl.)
  • affected from 5ab829f1971dc99f2aac10846c378e67fc875abc to 4224dccd325a9380e8edfb66aad8bb5771c94222 (excl.)
  • affected from 5ab829f1971dc99f2aac10846c378e67fc875abc to 2a79365b2278f16e163e4024086105693b421601 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.18 is affected
  • unaffected from 0 to 6.18 (excl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References