Junglewise Threat Intelligence

CVE-2026-90279: Linux kernel md/raid5 bitmap sector mapping calculation error

CVE-2026-90279 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RAID5 storage subsystem contained a logic error in how it aligned disk write operations to stripe boundaries. When using certain RAID5 configurations (such as 4 disks with 1024-sector chunks), the kernel could incorrectly map write ranges to physical disk sectors, potentially leading to data written to wrong locations or data integrity issues.

Technical details

The vulnerability exists in the raid5_bitmap_sector_map() function in drivers/md/raid5.c. The function uses round_down() and round_up() macros to align array sector ranges to full RAID5 stripe widths (chunk_sectors × number of data disks). However, because stripe width is not always a power of two, these mask-based rounding operations produce incorrect results. For example, with a 3072-sector stripe width, a write at sector 3072 was incorrectly mapped to the range [0, 1024) instead of the correct [1024, 2048). The fix replaces mask-based rounding with sector_div()-based arithmetic to correctly align to non-power-of-two stripe widths. This is a localized calculation bug requiring no authentication; impact is on data placement accuracy during RAID5 operations.

Affected products

  • Linux Linux Kernel multiple versions prior to fix commit 17ea021ae74987d6064c8195c4922fa025753892

Timeline

  • 2026-09-17: disclosed
  • 2026-08-03: patched: Fix commit 17ea021ae74987d6064c8195c4922fa025753892 authored

References

Related threats