Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: fix percpu_ref not resurrected on suspend timeout When llbitmap_suspend_timeout() times out waiting for percpu_ref to become zero, it returns -ETIMEDOUT without resurrecting the percpu_ref. The caller (md_llbitmap_daemon_fn) then continues to the next page without calling llbitmap_resume(), leaving the percpu_ref in a killed state permanently. Fix this by resurrecting the percpu_ref before returning the error, ensuring the page control structure remains usable for subsequent operations.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.18, < 6.18.14 |
References
- https://git.kernel.org/stable/c/095417d6b669c2dec39a5842ccb94df915f97f54Patch
- https://git.kernel.org/stable/c/2446d099350185caeed19ab2c0270451a97296fbPatch
- https://git.kernel.org/stable/c/d119bd2e1643cc023210ff3c6f0657e4f914e71dPatch
FAQ
What is CVE-2026-45955?
CVE-2026-45955 is a vulnerability with a CVSS score of 7.1 (HIGH). In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: fix percpu_ref not resurrected on suspend timeout When llbitmap_suspend_timeout() times out waiting for percpu_ref...
How severe is CVE-2026-45955?
CVE-2026-45955 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45955?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.