{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  md: recheck spare changes before starting sync  remove_spares() and remove_and_add_spares() modify the array's rdev configuration. These operations are only safe after the array has been suspended.  md_start_sync() checks whether spare configuration changes are needed before taking reconfig_mutex. However, the rdev state can change before the mutex is acquired, so the initial check can become stale. In that case, md_choose_sync_action() may remove or replace rdevs while normal I/O is still accessing them.  The race can occur as follows:  raid10d          Worker                      Normal IO ____________     _______________________     ______________________                                               raid10_write_request()                                              wait_blocked_dev() set Blocked set Faulty                                              Skip Faulty rdev                                              rrdev-\u003enr_pending++                                              .repl_bio = bio                  removeable_rdev = false     .                  array not suspended         . lock mddev                                   goto err_handle                  lock mddev (wait)                  . update sb        . clear Blocked    .                  . unlock mddev     .                  lock mddev (acquires)                  remove_spares()                  removeable_rdev = true                   raid10_remove_disk()                  rdev = replacement                  replacement = NULL                                              rdev_dec_pending(NULL)                  unlock mddev                (NULL)-\u003enr_pending--  In this case, rdev_dec_pending() is called with a NULL pointer, resulting in a NULL pointer dereference when attempting to decrement nr_pending.  Fix this by suspending the array when spare configuration changes are needed, including for non-read-write arrays, and checking again after taking reconfig_mutex. If the array was not already suspended and a change is now needed, release the mutex, suspend the array, and reacquire the mutex before continuing.",
  "id": "DEBIAN-CVE-2026-90400",
  "modified": "2026-09-18T04:47:34.584111073Z",
  "published": "2026-09-17T17:17:39.753Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-90400"
    }
  ],
  "upstream": [
    "CVE-2026-90400"
  ]
}