CVE-2026-90400 PUBLISHED

md: recheck spare changes before starting sync

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

md: recheck spare changes before starting sync

remove_spares() and remove_and_add_spares() modify the array's rdev configuration. These operations are only safe after the array has been suspended.

md_start_sync() checks whether spare configuration changes are needed before taking reconfig_mutex. However, the rdev state can change before the mutex is acquired, so the initial check can become stale. In that case, md_choose_sync_action() may remove or replace rdevs while normal I/O is still accessing them.

The race can occur as follows:

raid10d Worker Normal IO __ ___ ____

<pre> raid10_write_request() wait_blocked_dev() </pre>

set Blocked set Faulty Skip Faulty rdev rrdev->nr_pending++ .repl_bio = bio removeable_rdev = false . array not suspended . lock mddev goto err_handle lock mddev (wait) . update sb . clear Blocked . . unlock mddev . lock mddev (acquires) remove_spares() removeable_rdev = true

<pre> raid10_remove_disk() rdev = replacement replacement = NULL rdev_dec_pending(NULL) unlock mddev (NULL)->nr_pending-- </pre>

In this case, rdev_dec_pending() is called with a NULL pointer, resulting in a NULL pointer dereference when attempting to decrement nr_pending.

Fix this by suspending the array when spare configuration changes are needed, including for non-read-write arrays, and checking again after taking reconfig_mutex. If the array was not already suspended and a change is now needed, release the mutex, suspend the array, and reacquire the mutex before continuing.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from bc08041b32abe6c9824f78735bac22018eabfc06 to c3777d16bc3335c0ac4bdad0551c80d38c5d94cc (excl.)
  • affected from bc08041b32abe6c9824f78735bac22018eabfc06 to e5ac7ab78467b064f1da8b0f3042a63595fafcfd (excl.)
  • affected from bc08041b32abe6c9824f78735bac22018eabfc06 to 81b39df5d701976cf20e52f33106c1fc1603b4cb (excl.)
  • affected from bc08041b32abe6c9824f78735bac22018eabfc06 to c7d34d17ea43ebc86b45d439ebb435e11ca44bca (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.7 is affected
  • unaffected from 0 to 6.7 (excl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References