Junglewise Threat Intelligence

CVE-2026-46095: Linux Kernel race condition in md-llbitmap state machine transition

CVE-2026-46095 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition was identified in the Linux kernel's Multiple Device (MD) driver, which manages software RAID storage. This flaw could potentially lead to data corruption or system instability during disk write or discard operations. The issue has been resolved by ensuring proper synchronization barriers are in place before the system transitions between different operational states.

Technical details

A race condition exists in the md-llbitmap component of the Linux kernel's MD (Multiple Device) driver. The vulnerability occurs because the 'barrier raise' operation was previously called after the llbitmap_state_machine() function in both llbitmap_start_write() and llbitmap_start_discard(). This ordering allowed for a window where a state transition could complete before the necessary synchronization barrier was established. An attacker or a high-load scenario could trigger this race, potentially leading to inconsistent bitmap states or data corruption. The fix reorders these operations to ensure the barrier is raised before the state machine transition begins.

Affected products

  • Linux Linux Kernel Introduced in 5ab829f1971d; fixed in various stable branches including 9142f00a, 9701d51d, and ef4ca3d4

Timeline

  • 2026-02-23: other: Patch authored by Yu Kuai
  • 2026-05-27: disclosed: CVE published by kernel.org

References

Related threats