CVE-2026-90385

Source
https://cve.org/CVERecord?id=CVE-2026-90385
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90385.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90385
Downstream
Published
2026-09-17T16:09:21Z
Modified
2026-09-18T03:48:37Z
Summary
md/raid1: create serial pool adding rdev to array with serialize_policy=1
Details

In the Linux kernel, the following vulnerability has been resolved:

md/raid1: create serial pool adding rdev to array with serialize_policy=1

The following bug has been observed with kernel 7.1.3 after adding a new rdev to an existing RAID1 array with serialize_policy enabled:

Oops: 0002 [#1] CPU: 0 UID: 0 PID: 19639 Comm: ext4lazyinit Not tainted 7.1.3-1-default RIP: _raw_spin_lock_irqsave+0x27/0x50 CR2: 0000000000004960 Call Trace: wait_for_serialization+0xb9/0x260 [raid1] raid1_make_request+0x762/0xaff [raid1] md_handle_request+0x1c9/0x2e0 [md_mod]

The raid1.c code calls wait_for_serialization() if the MD_SERIALIZE_POLICY is set, and wait_for_serialization assumes that rdev->serial is initialized. Normally this will be the case for arrays that have the serialize_policy sysfs attribute set to 1.

But when a new rdev is added to an existing array in bind_rdev_to_array(), the condition at mddev_create_serial_pool() causes creation of rdev->serial to be skipped. Fix it.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90385.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
69b00b5bb23552d43e8bbed73ef6624604bb94a2
Fixed
f9e4364449f7ca6917f3599eb32064dba5b7b147
Fixed
37f11973c3eb72a5eb061082cad529bb6939c24f
Fixed
c02d675e81468003e4f2253b616c53729070d712
Fixed
140234b2380ffb8ffb0cfc46fee0e822f43adef7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90385.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.6.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90385.json"