CVE-2026-46051 Details
Description
In the Linux kernel, the following vulnerability has been resolved: md/raid5: fix soft lockup in retry_aligned_read() When retry_aligned_read() encounters an overlapped stripe, it releases the stripe via raid5_release_stripe() which puts it on the lockless released_stripes llist. In the next raid5d loop iteration, release_stripe_list() drains the stripe onto handle_list (since STRIPE_HANDLE is set by the original IO), but retry_aligned_read() runs before handle_active_stripes() and removes the stripe from handle_list via find_get_stripe() -> list_del_init(). This prevents handle_stripe() from ever processing the stripe to resolve the overlap, causing an infinite loop and soft lockup. Fix this by using __release_stripe() with temp_inactive_list instead of raid5_release_stripe() in the failure path, so the stripe does not go through the released_stripes llist. This allows raid5d to break out of its loop, and the overlap will be resolved when the stripe is eventually processed by handle_stripe().
A vulnerability in the Linux kernel's RAID5 handling has been addressed, which caused a soft lockup by creating an infinite loop during the retry of aligned read operations. This issue occurred when the 'retry_aligned_read()' function encountered an overlapped stripe. The function would release the stripe, but the subsequent processing loop failed to handle the overlap, leading to a deadlock. The vulnerability affected the Linux kernel's stable releases.
Users can upgrade to the latest stable version of the Linux kernel, where this vulnerability has been fixed. Instructions for downloading the latest version can be found on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/09880592f5a9dc73377d6eb5ac123537b5f8df49 | kernel.org | Patch |
| https://git.kernel.org/stable/c/1985cb3247e87ff6b8ca4bc5f9626f4f51024507 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4166d5234fe8b6c3c7f796a6c198605356c5b355 | kernel.org | Patch |
| https://git.kernel.org/stable/c/66df9f30673db66ac35145820a8e24906069ae57 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7f9f7c697474268d9ef9479df3ddfe7cdcfbbffc | kernel.org | Patch |
| https://git.kernel.org/stable/c/80fc6ca2cbde018d52e13f305edcd643911bd94b | kernel.org | Patch |
| https://git.kernel.org/stable/c/883cc33b7af1c448663287f069ef9dfea001e90f | kernel.org | Patch |
| https://git.kernel.org/stable/c/a9055300e07d9d6800264d3c2560e1d0144689ca | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-667 | Improper Locking | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.12, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.140 >= 6.7, < 6.12.86 >= 6.13, < 6.18.27 >= 6.19, < 7.0.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | CVE Modified | kernel.org |
| May 27, 2026 | New CVE Received | kernel.org |