Executive brief
A vulnerability in the Linux kernel's RAID5 storage driver can lead to a system hang or 'soft lockup.' This occurs when the system incorrectly handles specific data reading retries, causing the processor to enter an infinite loop. If exploited, this could result in a complete denial of service for the affected server, impacting data availability and business operations.
Technical details
A vulnerability in the Linux kernel's md/raid5 driver exists due to a logic error in retry_aligned_read(). When encountering an overlapped stripe, the function releases the stripe using raid5_release_stripe(), which places it on a lockless list. Subsequent processing in raid5d removes the stripe from the handle_list before it can be properly resolved, leading to an infinite loop and a soft lockup. This issue was introduced by the transition to lockless stripe releasing. The fix involves using __release_stripe() with a temporary inactive list to ensure the stripe bypasses the problematic lockless list and is correctly processed. Patches have been merged into multiple stable kernel branches.
Affected products
- Linux Linux Kernel Fixed in 09880592f5a9, 1985cb3247e8, 7f9f7c697474, 80fc6ca2cbde, 883cc33b7af1
Timeline
- 2026-04-02: other: Vulnerability fixed in upstream source code
- 2026-05-27: advisory: CVE-2026-46051 published by NVD
References
- https://git.kernel.org/stable/c/09880592f5a9dc73377d6eb5ac123537b5f8df49
- https://git.kernel.org/stable/c/1985cb3247e87ff6b8ca4bc5f9626f4f51024507
- https://git.kernel.org/stable/c/7f9f7c697474268d9ef9479df3ddfe7cdcfbbffc
- https://git.kernel.org/stable/c/80fc6ca2cbde018d52e13f305edcd643911bd94b
- https://git.kernel.org/stable/c/883cc33b7af1c448663287f069ef9dfea001e90f