CVE-2026-90385

In the Linux kernel, the following vulnerability has been resolved: md/raid1: create serial pool adding rdev to array with serialize_policy=1 The following bug has been observed with kernel 7.1.3 after adding a new rdev to an existing RAID1 array with serialize_policy enabled: Oops: 0002 [#1] CPU: 0 UID: 0 PID: 19639 Comm: ext4lazyinit Not tainted 7.1.3-1-default RIP: _raw_spin_lock_irqsave+0x27/0x50 CR2: 0000000000004960 Call Trace: wait_for_serialization+0xb9/0x260 [raid1] raid1_make_request+0x762/0xaff [raid1] md_handle_request+0x1c9/0x2e0 [md_mod] The raid1.c code calls wait_for_serialization() if the MD_SERIALIZE_POLICY is set, and wait_for_serialization assumes that rdev->serial is initialized. Normally this will be the case for arrays that have the serialize_policy sysfs attribute set to 1. But when a new rdev is added to an existing array in bind_rdev_to_array(), the condition at mddev_create_serial_pool() causes creation of rdev->serial to be skipped. Fix it.

Package Linux Kernel
Published 2026-09-17
Last modified 2026-09-17
Patch available
Yes

Affected versions

Linux kernel versions 5.6 and later are affected. Fixed in 6.12.110, 6.18.52, 7.2.6, 7.3-rc1 and their respective stable series.

Affected from
≥ 5.6
Fixed in
✓ 6.12.110 6.12.x ✓ 6.18.52 6.18.x ✓ 7.2.6 7.2.x ✓ 7.3-rc1

Frequently asked questions

  • What is CVE-2026-90385?

    CVE-2026-90385 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.6 onward and has been patched in 6.12.110, 6.18.52, 7.2.6 and others. CVE-2026-90385 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-90385?

    Yes. CVE-2026-90385 has been patched. Fixed versions include 6.12.110, 6.18.52, 7.2.6 and others. If you are running Linux kernel 5.6 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-90385 actively exploited?

    No. CVE-2026-90385 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.