CVE-2024-43914 Details
Description
In the Linux kernel, the following vulnerability has been resolved: md/raid5: avoid BUG_ON() while continue reshape after reassembling Currently, mdadm support --revert-reshape to abort the reshape while reassembling, as the test 07revert-grow. However, following BUG_ON() can be triggerred by the test: kernel BUG at drivers/md/raid5.c:6278! invalid opcode: 0000 [#1] PREEMPT SMP PTI irq event stamp: 158985 CPU: 6 PID: 891 Comm: md0_reshape Not tainted 6.9.0-03335-g7592a0b0049a #94 RIP: 0010:reshape_request+0x3f1/0xe60 Call Trace: <TASK> raid5_sync_request+0x43d/0x550 md_do_sync+0xb7a/0x2110 md_thread+0x294/0x2b0 kthread+0x147/0x1c0 ret_from_fork+0x59/0x70 ret_from_fork_asm+0x1a/0x30 </TASK> Root cause is that --revert-reshape update the raid_disks from 5 to 4, while reshape position is still set, and after reassembling the array, reshape position will be read from super block, then during reshape the checking of 'writepos' that is caculated by old reshape position will fail. Fix this panic the easy way first, by converting the BUG_ON() to WARN_ON(), and stop the reshape if checkings fail. Noted that mdadm must fix --revert-shape as well, and probably md/raid should enhance metadata validation as well, however this means reassemble will fail and there must be user tools to fix the wrong metadata.
A vulnerability in the Linux kernel's md/raid5 component can lead to a kernel panic. This issue arises when the mdadm tool is used to revert a reshape operation while the array is being reassembled. The problem occurs because the revert action updates the number of active disks in the RAID array, but the reshape position remains unchanged. When the array is reassembled, the old reshape position is read, causing a mismatch that triggers a BUG_ON() condition, leading to a kernel crash. The vulnerability has been addressed by changing the BUG_ON() calls to WARN_ON() and halting the reshape process if the checks fail.
Users can upgrade to the latest Linux kernel version, which includes the necessary fix. For Debian 11, this update is available in the linux package version 5.10.226-1. Users can also upgrade to Linux 6.1, which is available as a separate package.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 10, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | < 4.19.320 >= 4.20, < 5.4.282 >= 5.5, < 5.10.224 >= 5.11, < 5.15.165 >= 5.16, < 6.1.105 >= 6.2, < 6.6.46 >= 6.7, < 6.10.5 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Sep 5, 2024 | Initial Analysis | [email protected] |
| Aug 26, 2024 | New CVE Received | kernel.org |