dm: fix resume-vs-remove race
Published Sep 16, 2026
7.8
HIGHCVSS 3.1
EPSS 0.17%
Description
If the user issues the resume ioctl and the remove ioctl at the same time, it may be possible that the device is resumed after it is suspended in __dm_destroy. The result is that the table is destroyed without calling the postsuspend method.
Dm targets expect that they may be removed only after the postsuspend method method was called. If we break this expectation, it can cause misbehavior in various targets. For example - in the dm-integrity target, the reboot notifier is not unregistered, leading to use-after-free.
Fix this bug by refusing to resume if the device is being destroyed.
Affected products
-
- Version 2.6.35.4StatusaffectedConstraints<2.6.36
- Version
-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.36StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.36
- Version 5.10.270StatusunaffectedConstraints<=5.10.*
- Version 5.15.221StatusunaffectedConstraints<=5.15.*
- Version 6.1.188StatusunaffectedConstraints<=6.1.*
- Version 6.12.110StatusunaffectedConstraints<=6.12.*
- Version 6.18.51StatusunaffectedConstraints<=6.18.*
- Version 6.6.157StatusunaffectedConstraints<=6.6.*
- Version 7.2.5StatusunaffectedConstraints<=7.2.*
- Version 7.3-rc1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
Sep-Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.17% (0.00171) | 5.82th | v5 (v2026.06.15) |
| Sep 17, 2026 | 0.16% (0.00159) | 5.51th | v5 (v2026.06.15) |
No CWE recorded.
References (8)
- https://git.kernel.org/stable/c/1ede2bce2bd640605df83db1356fd727159bc9ed
- https://git.kernel.org/stable/c/36177beff2a9df035991ad8d16ccf8d363ed93ee
- https://git.kernel.org/stable/c/3b59530b14fde693e41d8e39bc326df6cbf07b76
- https://git.kernel.org/stable/c/3f04e6520d9a53adb1d1daf4dc5d31a60fc77d1f
- https://git.kernel.org/stable/c/44b43ec132f1cf3275ecc182d0c82f50c3c4c3d5
- https://git.kernel.org/stable/c/94380ecd5ff9b2a2b9f6e8a0b5c465159ccfaf71
- https://git.kernel.org/stable/c/94f3d399c1ddba763c1c5a6501f7375d533d789f
- https://git.kernel.org/stable/c/9757367bcf1d5d2c50b94d005abca21f3eedd7c3
Change history (0)
No recorded changes yet.