Junglewise Threat Intelligence

CVE-2026-53128: Linux Kernel DRBD unbalanced RCU calls in drbd_adm_dump_devices

CVE-2026-53128 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A synchronization issue was identified in the Linux kernel's Distributed Replicated Block Device (DRBD) driver, which is used for managing mirrored storage over a network. The flaw involves improper handling of internal locking mechanisms (RCU) when querying device status. While primarily a technical maintenance fix, such issues can theoretically lead to system instability or crashes under specific conditions.

Technical details

A vulnerability was identified in the Linux kernel DRBD driver where drbd_adm_dump_devices() and drbd_adm_dump_peer_devices() failed to properly balance RCU read-side critical sections. Specifically, the code could reach an rcu_read_unlock() call without a preceding rcu_read_lock() when a resource filter was specified but the resource was not found. This was detected using the Clang thread-safety analyzer. An attacker with local access could potentially trigger this code path to cause kernel synchronization inconsistencies. The issue has been resolved by ensuring rcu_read_lock() is called before jumping to the cleanup label in error paths.

Affected products

  • Linux Linux Kernel 4.5 to 6.14

Timeline

  • 2026-03-26: disclosed: Initial patch submitted by Bart Van Assche
  • 2026-06-24: advisory: CVE-2026-53128 published by NVD

References

Related threats