Executive brief
A synchronization issue was identified in the Linux kernel's Distributed Replicated Block Device (DRBD) driver, which is used for managing mirrored storage over a network. The flaw involves improper handling of internal locking mechanisms (RCU) when querying device status. While primarily a technical maintenance fix, such issues can theoretically lead to system instability or crashes under specific conditions.
Technical details
A vulnerability was identified in the Linux kernel DRBD driver where drbd_adm_dump_devices() and drbd_adm_dump_peer_devices() failed to properly balance RCU read-side critical sections. Specifically, the code could reach an rcu_read_unlock() call without a preceding rcu_read_lock() when a resource filter was specified but the resource was not found. This was detected using the Clang thread-safety analyzer. An attacker with local access could potentially trigger this code path to cause kernel synchronization inconsistencies. The issue has been resolved by ensuring rcu_read_lock() is called before jumping to the cleanup label in error paths.
Affected products
- Linux Linux Kernel 4.5 to 6.14
Timeline
- 2026-03-26: disclosed: Initial patch submitted by Bart Van Assche
- 2026-06-24: advisory: CVE-2026-53128 published by NVD
References
- https://git.kernel.org/stable/c/1f112240531f0a0b437b2e001c1d89e8b25a8328
- https://git.kernel.org/stable/c/282e06e6d494a7bee85af78c747527b7d4009cc3
- https://git.kernel.org/stable/c/2b31e86387e60b3689339f0f0fbb4d3623d9d494
- https://git.kernel.org/stable/c/68ebb9183ac3621b96b18e046841eadb9508783c
- https://git.kernel.org/stable/c/6cd27bcb71bb73f955d104cc3a62be6f83724392
- https://git.kernel.org/stable/c/8092713a10c19fa0f731b71b2853af4319ca54fd
- https://git.kernel.org/stable/c/996d279f2c985d771d6cfdd923e447d825726e06