PT-2026-94733 · Linux · Linux Kernel

CVE-2026-90385

·

Published

2026-09-17

·

Updated

2026-09-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel version 7.1.3
Description An issue exists in the md/raid1 component where adding a new rdev to an existing RAID1 array with the serialize policy enabled can lead to a system crash. This occurs because the bind rdev to array() function, via a condition in mddev create serial pool(), may skip the initialization of rdev->serial. Subsequently, when the wait for serialization() function is called, it incorrectly assumes that rdev->serial is initialized, resulting in a null pointer dereference during the execution of raw spin lock irqsave().
Recommendations Update Linux kernel version 7.1.3 to a version where this issue is resolved.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102096
CVE-2026-90385
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel