Improper initialization in Linux kernel - CVE-2026-90385
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to improper initialization in the md/raid1 serial pool creation logic when adding a new rdev to an existing RAID1 array with serialize policy enabled. A local privileged user can add a new rdev to a configured RAID1 array to cause a denial of service.