Executive brief
The Linux kernel's MD RAID1 and RAID10 drivers contain a deadlock condition in their read error recovery path. When an array is suspended and a split bio is resubmitted during error handling, the system can deadlock if it attempts to acquire a reference twice to the same active I/O counter. This affects the availability of systems using software RAID1 or RAID10 storage arrays, potentially causing them to hang when errors occur during normal operation.
Technical details
The vulnerability is a deadlock in the MD RAID subsystem's read error handling path. When raid1d or raid10d resubmit a cloned bio while handling read errors, and the array is suspended before md_handle_request() can acquire an active_io reference, a deadlock occurs because the cloned bio already holds an active_io reference. The code path attempts to acquire another reference via percpu_ref_tryget_live(), which fails to progress while the array is suspended. The fix introduces a check (md_cloned_bio) to detect MD cloned bios and uses percpu_ref_get() directly for them instead of percpu_ref_tryget_live(), avoiding the deadlock condition. No user interaction or privilege escalation is required; the condition can occur during normal array operation.
Affected products
- Linux Linux kernel Multiple versions (see git stable branches)
Timeline
- 2026-08-15: disclosed
- 2026-05-01: patched: Fix committed upstream; backported to stable branches