CVE-2026-43271 Details
Description
In the Linux kernel, the following vulnerability has been resolved: md-cluster: fix NULL pointer dereference in process_metadata_update The function process_metadata_update() blindly dereferences the 'thread' pointer (acquired via rcu_dereference_protected) within the wait_event() macro. While the code comment states "daemon thread must exist", there is a valid race condition window during the MD array startup sequence (md_run): 1. bitmap_load() is called, which invokes md_cluster_ops->join(). 2. join() starts the "cluster_recv" thread (recv_daemon). 3. At this point, recv_daemon is active and processing messages. 4. However, mddev->thread (the main MD thread) is not initialized until later in md_run(). If a METADATA_UPDATED message is received from a remote node during this specific window, process_metadata_update() will be called while mddev->thread is still NULL, leading to a kernel panic. To fix this, we must validate the 'thread' pointer. If it is NULL, we release the held lock (no_new_dev_lockres) and return early, safely ignoring the update request as the array is not yet fully ready to process it.
A NULL pointer dereference vulnerability has been identified in the Linux kernel's MD cluster management. The issue arises in the 'process_metadata_update()' function, which improperly dereferences the 'thread' pointer without adequate validation. This flaw can lead to a kernel panic under specific conditions. During the startup sequence of an MD array, a race condition can occur where a 'METADATA_UPDATED' message is received from a remote node before the main MD thread is initialized. As a result, the 'process_metadata_update()' function is called with a NULL thread pointer, causing a system crash.
The vulnerability has been addressed in the official Linux Git repository. Users can upgrade to the latest version to apply the fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/721599e837d3f4c0e6cc14da059612c017b6d3ec | kernel.org | Patch |
| https://git.kernel.org/stable/c/a61c1bc84c4a0f1e7c2fe55b0f43d7d94af4adf1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/dceb5a843910004cb118148e267036104fc3ee43 | kernel.org | Patch |
| https://git.kernel.org/stable/c/dec123825c1ed74d98fd5fc7571a851dea4f46ff | kernel.org | Patch |
| https://git.kernel.org/stable/c/f150e753cb8dd756085f46e86f2c35ce472e0a3c | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.12, < 6.6.128 >= 6.7, < 6.12.75 >= 6.13, < 6.18.16 >= 6.19, < 6.19.6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 8, 2026 | Initial Analysis | [email protected] |
| May 6, 2026 | New CVE Received | kernel.org |