CVE-2026-90385
CVE CVE-2026-90385EUVD EUVD-2026-82046Published 2026-09-17T16:09:21.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: md/raid1: create serial pool adding rdev to array with serialize_policy=1 The following bug has been observed with kernel 7.1.3 after adding a new rdev to an existing RAID1 array with serialize_policy enabled: Oops: 0002 [#1] CPU: 0 UID: 0 PID: 19639 Comm: ext4lazyinit Not tainted 7.1.3-1-default RIP: _raw_spin_lock_irqsave+0x27/0x50 CR2: 0000000000004960 Call Trace: wait_for_serialization+0xb9/0x260 [raid1] raid1_make_request+0x762/0xaff [raid1] md_handle_request+0x1c9/0x2e0 [md_mod] The raid1.c code calls wait_for_serialization() if the MD_SERIALIZE_POLICY is set, and wait_for_serialization assumes that rdev->serial is initialized. Normally this will be the case for arrays that have the serialize_policy sysfs attribute set to 1. But when a new rdev is added to an existing array in bind_rdev_to_array(), the condition at mddev_create_serial_pool() causes creation of rdev->serial to be skipped. Fix it.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.18.52; 69b00b5bb23552d43e8bbed73ef6624604bb94a2 <140234b2380ffb8ffb0cfc46fee0e822f43adef7; 5.6; 69b00b5bb23552d43e8bbed73ef6624604bb94a2 <c02d675e81468003e4f2253b616c53729070d712; patch: 0; patch: 6.12.110; patch: 7.2.6; patch: 7.3-rc1; 69b00b5bb23552d43e8bbed73ef6624604bb94a2 <f9e4364449f7ca6917f3599eb32064dba5b7b147; 69b00b5bb23552d43e8bbed73ef6624604bb94a2 <37f11973c3eb72a5eb061082cad529bb6939c24f
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.