CVE-2026-90385 | Linux Kernel up to 6.12.109/6.18.51/7.2.5 raid1 raid1.c mddev_create_serial_pool rdev->serial null pointer dereference

SecurityVulns

A vulnerability was found in Linux Kernel up to 6.12.109/6.18.51/7.2.5. It has been declared as problematic. Affected is the function mddev_create_serial_pool of the file raid1.c of the component raid1. The manipulation of the argument rdev->serial results in null pointer dereference.

This vulnerability is cataloged as CVE-2026-90385. The attack must be initiated from a local position. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More