Improper access control in Linux kernel - CVE-2026-46045
Published: May 28, 2026
Vulnerability details
The vulnerability allows a local user to cause data corruption.
The vulnerability exists due to improper access control in md-llbitmap when reading bitmap pages from member disks. A local user can cause the system to read bitmap data from a spare disk that is still being rebuilt to cause data corruption.
The issue occurs because disks that are not fully synchronized may be treated as valid bitmap sources.
Affected software
Ubuntu
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-raspi (Ubuntu package)
How to mitigate CVE-2026-46045
linux (Ubuntu package) - update to 7.0.0-27.27
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1010.10
linux-nvidia (Ubuntu package) - update to 7.0.0-1013.13
linux-raspi (Ubuntu package) - update to 7.0.0-1014.14