{"id":"CVE-2026-90278","published":"2026-09-17T17:17:24.460","lastModified":"2026-09-17T17:17:24.460","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd: wait for behind writes before destroying bitmap\n\n__md_stop() destroyed the bitmap before calling mddev_detach(). That made\nmddev_detach() skip bitmap_ops->wait_behind_writes(), because the bitmap\nwas already disconnected from mddev.\n\nThis was still safe for the legacy bitmap because bitmap_destroy() waits\nfor behind writes itself. llbitmap keeps that wait in its\n->wait_behind_writes() operation instead, while ->destroy() tears down the\nllbitmap storage. With the old ordering, RAID1 behind-write completions\ncould still run after llbitmap storage had been freed.\n\nCall mddev_detach() before md_bitmap_destroy() so the common detach path\ncan wait for behind writes while the bitmap is still alive. Only destroy\nthe bitmap after those users are gone.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/2a79365b2278f16e163e4024086105693b421601","tags":[]},{"url":"https://git.kernel.org/stable/c/4224dccd325a9380e8edfb66aad8bb5771c94222","tags":[]},{"url":"https://git.kernel.org/stable/c/73881ff7a75913f919a1ce9d9571bfaab8e8588d","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}