Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-53123

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/06/2026
Última modificación:
23/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> md: wake raid456 reshape waiters before suspend<br /> <br /> During raid456 reshape, direct IO across the reshape position can sleep<br /> in raid5_make_request() waiting for reshape progress while still<br /> holding an active_io reference. If userspace then freezes reshape and<br /> writes md/suspend_lo or md/suspend_hi, mddev_suspend() kills active_io<br /> and waits for all in-flight IO to drain.<br /> <br /> This can deadlock: the IO needs reshape progress to continue, but the<br /> reshape thread is already frozen, so the active_io reference is never<br /> dropped and suspend never completes.<br /> <br /> raid5_prepare_suspend() already wakes wait_for_reshape for dm-raid. Do<br /> the same for normal md suspend when reshape is already interrupted, so<br /> waiting raid456 IO can abort, drop its reference, and let suspend<br /> finish.<br /> <br /> The mdadm test tests/25raid456-reshape-deadlock reproduces the hang.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.91 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.33 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.10 (excluyendo)