Back

HIGH

dm: fix race when loading and unloading a table

Published Sep 16, 2026

Description

If the userspace calls two concurrent table load ioctls and one of them succeeds and the other fails, there is a race condition because dm_setup_md_queue walks &md->table_devices without any lock. If the walk races with dm_table_destroy -> free_devices -> dm_put_table_device, there is access to invalid memory.

Fix this race by extending the lock over the list walk.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Sep 16, 2026
Updated Sep 17, 2026
Reserved Sep 11, 2026

CISA Vulnrichment

No data

NVD

Status Received
Modified Sep 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Linux
Published Sep 16, 2026
Updated Sep 17, 2026

GitHub

No data