CVE-2026-90389
CVE CVE-2026-90389EUVD EUVD-2026-82050Published 2026-09-17T16:09:23.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: md: scope memalloc_noio to allocation critical sections Storing a memalloc_noio_save() token in mddev->noio_flags lets one task save the token and another task restore it. With concurrent suspend sysfs writes, task A can enter PF_MEMALLOC_NOIO, return to userspace still in that scope, and later task B can restore A's saved token. Avoid tying the token lifetime to mddev. Keep mddev_suspend() and mddev_resume() only responsible for array suspension, and enter PF_MEMALLOC_NOIO only in the MD paths that allocate memory after the array has been suspended. Restore the token before resuming the array. A reproducer repeatedly writes suspend_lo and suspend_hi from concurrent workers and checks each worker's /proc/self/stat flags before and after the sysfs write.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 78f57ef9d50a75326da73d352d7c27828495229a <bace2010dd7ac07bc980575afb135c406730a7fe; patch: 0; 78f57ef9d50a75326da73d352d7c27828495229a <28fdea874f68cac6c36651b1fc7272fd2199c48d; patch: 7.2.6; patch: 6.12.110; 78f57ef9d50a75326da73d352d7c27828495229a <72ebfdf507ede7d7f2b7ca0a5634811a0e4bf045; patch: 7.3-rc1; 5.8; patch: 6.18.52; 78f57ef9d50a75326da73d352d7c27828495229a <a58923756b0f8e71032070c23ae0b167e46731da
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.