In the Linux kernel, the following vulnerability has been resolved:
md/md-llbitmap: skip reading rdevs that are not in_sync
When reading bitmap pages from member disks, the code iterates through all rdevs and attempts to read from the first available one. However, it only checks for raid_disk assignment and Faulty flag, missing the In_sync flag check.
This can cause bitmap data to be read from spare disks that are still being rebuilt and don't have valid bitmap information yet. Reading stale or uninitialized bitmap data from such disks can lead to incorrect dirty bit tracking, potentially causing data corruption during recovery or normal operation.
Add the In_sync flag check to ensure bitmap pages are only read from fully synchronized member disks that have valid bitmap data.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.18-tools-debuginfoUpgrade python3-perf6.18-debuginfoUpgrade kernel6.18-modules-extra-commonUpgrade perf6.18Upgrade python3-perf6.18Upgrade kernel6.18-debuginfo-common-aarch64Upgrade bpftool6.18Upgrade kernel6.18Upgrade kernel-livepatch-6.18.30-61.116Upgrade perf6.18-debuginfoUpgrade bpftool6.18-debuginfoUpgrade kernel6.18-tools-develUpgrade kernel6.18-modules-extraUpgrade kernel6.18-headersUpgrade kernel6.18-toolsUpgrade kernel6.18-develUpgrade kernel6.18-debuginfoUpgrade kernel6.18-debuginfo-common-x86_64 | Jun 23, 2026 | May 27, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 27, 2026 |
| Ubuntu | — | Upgrade linux-image-realtime-64k-hwe-26.04Upgrade linux-image-oem-7.0Upgrade linux-image-realtimeUpgrade linux-image-generic-hwe-26.04Upgrade linux-image-7.0.0-27-realtime-64kUpgrade linux-image-azure-7.0Upgrade linux-image-gcpUpgrade linux-image-oracle-64k-7.0Upgrade linux-image-gcp-64k-7.0Upgrade linux-image-oracle-64kUpgrade linux-image-oem-24.04cUpgrade linux-image-realtime-64kUpgrade linux-image-virtual-7.0Upgrade linux-image-azure-fdeUpgrade linux-image-nvidia-7.0Upgrade linux-image-7.0.0-1008-oemUpgrade linux-image-oem-24.04dUpgrade linux-image-generic-7.0Upgrade linux-image-7.0.0-1008-awsUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-7.0.0-27-realtimeUpgrade linux-image-oem-26.04aUpgrade linux-image-raspi-7.0Upgrade linux-image-oracleUpgrade linux-image-raspi-realtimeUpgrade linux-image-7.0.0-1014-raspiUpgrade linux-image-7.0.0-28-genericUpgrade linux-image-7.0.0-27-genericUpgrade linux-image-7.0.0-1007-oracleUpgrade linux-image-gcp-64kUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-7.0.0-27-generic-64kUpgrade linux-image-virtualUpgrade linux-image-realtime-64k-7.0Upgrade linux-image-awsUpgrade linux-image-nvidia-64kUpgrade linux-image-oem-24.04aUpgrade linux-image-7.0.0-1010-azureUpgrade linux-image-aws-64kUpgrade linux-image-7.0.0-1009-ibmUpgrade linux-image-oem-26.04Upgrade linux-image-realtime-hwe-26.04Upgrade linux-image-realtime-7.0Upgrade linux-image-7.0.0-1008-aws-64kUpgrade linux-image-ibm-7.0Upgrade linux-image-7.0.0-1013-nvidiaUpgrade linux-image-generic-64k-hwe-26.04Upgrade linux-image-generic-64k-7.0Upgrade linux-image-generic-64kUpgrade linux-image-aws-64k-7.0Upgrade linux-image-7.0.0-1014-raspi-realtimeUpgrade linux-image-nvidiaUpgrade linux-image-azureUpgrade linux-image-raspi-realtime-7.0Upgrade linux-image-7.0.0-1007-gcpUpgrade linux-image-gcp-7.0Upgrade linux-image-raspiUpgrade linux-image-7.0.0-1007-gcp-64kUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-nvidia-64k-7.0Upgrade linux-image-azure-fde-7.0Upgrade linux-image-oem-24.04bUpgrade linux-image-oem-24.04Upgrade linux-image-virtual-hwe-26.04Upgrade linux-image-ibmUpgrade linux-image-genericUpgrade linux-image-oracle-7.0Upgrade linux-image-7.0.0-1013-nvidia-64kUpgrade linux-image-7.0.0-1009-azure-fdeUpgrade linux-image-7.0.0-28-generic-64kUpgrade linux-image-aws-7.0Upgrade linux-image-7.0.0-1007-oracle-64k | Jul 1, 2026 | May 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub