---
id: CVE-2026-90400
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  md: recheck spare changes before starting sync

  remove_spares() and remove_and_add_spares() modify the array's rdev
  configuration
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  md: recheck spare changes before starting sync

  remove_spares() and remove_and_add_spares() modify the array's rdev
  configuration. These operations are only safe after …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= bc08041b32abe6c9824f78735bac22018eabfc06 <
    c3777d16bc3335c0ac4bdad0551c80d38c5d94cc
  - >-
    Linux >= bc08041b32abe6c9824f78735bac22018eabfc06 <
    e5ac7ab78467b064f1da8b0f3042a63595fafcfd
  - >-
    Linux >= bc08041b32abe6c9824f78735bac22018eabfc06 <
    81b39df5d701976cf20e52f33106c1fc1603b4cb
  - >-
    Linux >= bc08041b32abe6c9824f78735bac22018eabfc06 <
    c7d34d17ea43ebc86b45d439ebb435e11ca44bca
  - Linux 6.7
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:39.753'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90400'
references:
  - url: 'https://git.kernel.org/stable/c/81b39df5d701976cf20e52f33106c1fc1603b4cb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c3777d16bc3335c0ac4bdad0551c80d38c5d94cc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c7d34d17ea43ebc86b45d439ebb435e11ca44bca'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e5ac7ab78467b064f1da8b0f3042a63595fafcfd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.800Z'
epss: 0.00209
epssPercentile: 0.09856
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

md: recheck spare changes before starting sync

remove_spares() and remove_and_add_spares() modify the array's rdev
configuration. These operations are only safe after the array has been
suspended.

md_start_sync() checks whether spare configuration changes are needed
before taking reconfig_mutex. However, the rdev state can change before
the mutex is acquired, so the initial check can become stale. In that
case, md_choose_sync_action() may remove or replace rdevs while normal
I/O is still accessing them.

The race can occur as follows:

raid10d          Worker                      Normal IO
____________     _______________________     ______________________

                                             raid10_write_request()
                                             wait_blocked_dev()
set Blocked
set Faulty
                                             Skip Faulty rdev
                                             rrdev->nr_pending++
                                             .repl_bio = bio
                 removeable_rdev = false     .
                 array not suspended         .
lock mddev                                   goto err_handle
                 lock mddev (wait)
                 .
update sb        .
clear Blocked    .
                 .
unlock mddev     .
                 lock mddev (acquires)
                 remove_spares()
                 removeable_rdev = true

                 raid10_remove_disk()
                 rdev = replacement
                 replacement = NULL
                                             rdev_dec_pending(NULL)
                 unlock mddev                (NULL)->nr_pending--

In this case, rdev_dec_pending() is called with a NULL pointer,
resulting in a NULL pointer dereference when attempting to decrement
nr_pending.

Fix this by suspending the array when spare configuration changes are
needed, including for non-read-write arrays, and checking again after
taking reconfig_mutex. If the array was not already suspended and a
change is now needed, release the mutex, suspend the array, and
reacquire the mutex before continuing.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
