{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.10-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  md: fix array_state=clear sysfs deadlock  When \"clear\" is written to array_state, md_attr_store() breaks sysfs active protection so the array can delete itself from its own sysfs store method.  However, md_attr_store() currently drops the mddev reference before calling sysfs_unbreak_active_protection(). Once do_md_stop(..., 0) has made the mddev eligible for delayed deletion, the temporary kobject reference taken by sysfs_break_active_protection() can become the last kobject reference protecting the md kobject.  That allows sysfs_unbreak_active_protection() to drop the last kobject reference from the current sysfs writer context. kobject teardown then recurses into kernfs removal while the current sysfs node is still being unwound, and lockdep reports recursive locking on kn-\u003eactive with kernfs_drain() in the call chain.  Reproducer on an existing level: 1. Create an md0 linear array and activate it:    mknod /dev/md0 b 9 0    echo none \u003e /sys/block/md0/md/metadata_version    echo linear \u003e /sys/block/md0/md/level    echo 1 \u003e /sys/block/md0/md/raid_disks    echo \"$(cat /sys/class/block/sdb/dev)\" \u003e /sys/block/md0/md/new_dev    echo \"$(($(cat /sys/class/block/sdb/size) / 2))\" \u003e \\ \t/sys/block/md0/md/dev-sdb/size    echo 0 \u003e /sys/block/md0/md/dev-sdb/slot    echo active \u003e /sys/block/md0/md/array_state 2. Wait briefly for the array to settle, then clear it:    sleep 2    echo clear \u003e /sys/block/md0/md/array_state  The warning looks like:    WARNING: possible recursive locking detected   bash/588 is trying to acquire lock:   (kn-\u003eactive#65) at __kernfs_remove+0x157/0x1d0   but task is already holding lock:   (kn-\u003eactive#65) at sysfs_unbreak_active_protection+0x1f/0x40   ...   Call Trace:    kernfs_drain    __kernfs_remove    kernfs_remove_by_name_ns    sysfs_remove_group    sysfs_remove_groups    __kobject_del    kobject_put    md_attr_store    kernfs_fop_write_iter    vfs_write    ksys_write  Restore active protection before mddev_put() so the extra sysfs kobject reference is dropped while the mddev is still held alive. The actual md kobject deletion is then deferred until after the sysfs write path has fully returned.",
  "id": "DEBIAN-CVE-2026-53125",
  "modified": "2026-09-14T16:47:44.921285317Z",
  "published": "2026-06-24T17:17:27.770Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-53125"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-53125"
  ]
}