Executive brief
The Linux kernel's mtip32xx driver (used for Micron RealSSD PCIe flash storage devices) contains a race condition between ioctl operations and device removal. When a device is being removed from the system, in-flight ioctl calls can dereference freed memory, potentially causing a crash or system instability. This could affect servers or storage systems using these flash devices.
Technical details
The vulnerability is a use-after-free race condition in the mtip32xx block driver's ioctl handlers. The ioctl code path tested the REMOVE_PENDING flag before acquiring synchronization, but device removal could set that bit and free the dd->port structure immediately after the check but before the ioctl handler finished, leading to a dereference of freed memory. The fix serializes ioctl operations (both native and compat ioctls) with device removal by introducing a mutex that is held from the start of removal through teardown of the port structure. Attack vector requires local access with an ability to trigger ioctls on an already-open block device while device removal is in progress.
Affected products
- Linux Linux kernel Multiple versions (fix applies to mtip32xx driver across stable branches 4.x, 5.x, 6.x, 7.x)
Timeline
- 2026-09-17: disclosed: CVE-2026-90180 published