Junglewise Threat Intelligence

CVE-2026-46327: Linux Kernel race condition in Device Mapper dm_blk_report_zones

CVE-2026-46327 · Severity: info · Published 2026-06-09

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition was identified in the Linux kernel's Device Mapper component, which manages storage volumes. Under specific timing conditions, the system might attempt to perform operations on a storage device while it is being suspended, potentially leading to unpredictable system behavior or errors. This issue has been resolved in recent kernel updates.

Technical details

A race condition exists in the dm_blk_report_zones function within the Linux kernel's Device Mapper (dm) subsystem. The function previously checked if a device was suspended using dm_suspended_md without holding the necessary locks, allowing the device state to change immediately after the check. This could result in operations being attempted on a suspended mapped device. The fix involves moving the dm_suspended_md check to occur after dm_get_live_table is called, ensuring the device state remains consistent during the operation. Patches have been merged into multiple stable kernel branches.

Affected products

  • Linux Linux Kernel All versions prior to the 2026 patches

Timeline

  • 2026-01-08: other: Patch authored
  • 2026-06-09: disclosed: CVE published

References

Related threats