Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-90276NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

md/md-llbitmap: stop daemon timer rearm on destroy

llbitmap_destroy() deletes pending_timer before flushing
md_llbitmap_io_wq. However, daemon_work can still be queued or running
after the timer has been deleted, and the daemon path can arm
pending_timer again when it finds dirty chunks that are not ready to
flush yet.

If that happens during teardown, pending_timer can remain armed after
llbitmap is freed and later dereference freed memory.

Add a BITMAP_SHUTDOWN bit to llbitmap->flags, set it before deleting
the timer, and make the timer and daemon paths stop queueing or rearming
work once teardown starts. Cancel daemon_work before flushing the shared
workqueue so no already queued daemon instance can race with the free.
Use timer_shutdown_sync() so a daemon instance that passed the shutdown
check before teardown cannot rearm the timer afterward.

BITMAP_SHUTDOWN is a runtime-only state. Mask it out when reading and
updating the llbitmap superblock so the shutdown state is never loaded
from disk or persisted to disk.
Severity Level
UNKNOWN
Published Date
Sep 17, 2026
Last Modified
Sep 17, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.20%Probability
Root Weakness (CWE)
N/A

Affected & Patched Versions

Affected Versions
  • Linux Linux >= 5ab829f1971dc99f2aac10846c378e67fc875abc and < c55aa6c17f019b6296952d336939891efa084c06
  • Linux Linux >= 5ab829f1971dc99f2aac10846c378e67fc875abc and < bb7f92d58fca9a9f06f3f51a82481c5f0bbbd46c
  • Linux Linux >= 5ab829f1971dc99f2aac10846c378e67fc875abc and < 5553d64e01d9a995be6c3de38501c6dd4ceede3b
  • Linux Linux >= 6.18
Patched Versions
  • Linux Linux c55aa6c17f019b6296952d336939891efa084c06
  • Linux Linux bb7f92d58fca9a9f06f3f51a82481c5f0bbbd46c
  • Linux Linux 5553d64e01d9a995be6c3de38501c6dd4ceede3b
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.