CVE-2026-45955
📛 CVE Title
md/md-llbitmap: fix percpu_ref not resurrected on suspend timeout
Description
In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: fix percpu_ref not resurrected on suspend timeout When llbitmap_suspend_timeout() times out waiting for percpu_ref to become zero, it returns -ETIMEDOUT without resurrecting the percpu_ref. The caller (md_llbitmap_daemon_fn) then continues to the next page without calling llbitmap_resume(), leaving the percpu_ref in a killed state permanently. Fix this by resurrecting the percpu_ref before returning the error, ensuring the page control structure remains usable for subsequent operations.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Linux
- CVSS severity
- high
- CVSS score
- 7.1 / 10
- CVSS vector
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H- Effective score
- 7.1 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- 2026-05-13
- Published
- 2026-05-27 12:18 UTC
- Last updated
- 2026-05-27 12:18 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/45xxx/CVE-2026-45955.json
- Linked Threat
- CVE-2026-45955 — CVE-2026-45955
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-05-27 14:17:12 UTC
- NVD last modified
- 2026-06-17 10:52:47 UTC
- NVD CVSS v3.1
- 7.1 / 10 HIGH source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H- Exploitability subscore
- 1.8 / 10
- Impact subscore
- 5.2 / 10
- EPSS score
- 0.0012 (probability of exploitation in next 30 days)
- EPSS percentile
- 2.53% vs all CVEs — higher = more likely to be exploited, as of 2026-07-26
NVD / KEV / EPSS data refreshed 2026-07-26 21:02 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-32239 - Assigner
- Linux
- Published
- May 27, 2026, 12:18:10 PM
- Updated
- Jun 5, 2026, 6:06:10 AM
- EUVD base score (CVSS 3.1)
-
7.1 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H - EUVD-reported EPSS
- 0.1200
- Vendors
- Linux
- Products
-
Linux (5ab829f1971dc99f2aac10846c378e67fc875abc <095417d6b669c2dec39a5842ccb94df915f97f54)Linux (5ab829f1971dc99f2aac10846c378e67fc875abc <d119bd2e1643cc023210ff3c6f0657e4f914e71d)Linux (patch: 7.0)Linux (5ab829f1971dc99f2aac10846c378e67fc875abc <2446d099350185caeed19ab2c0270451a97296fb)Linux (patch: 6.18.14)Linux (patch: 0)Linux (patch: 6.19.4)Linux (6.18)
- Aliases
-
GHSA-7293-q55v-843q
ENISA description: In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: fix percpu_ref not resurrected on suspend timeout When llbitmap_suspend_timeout() times out waiting for percpu_ref to become zero, it returns -ETIMEDOUT without resurrecting the percpu_ref. The caller (md_llbitmap_daemon_fn) then continues to the next page without calling llbitmap_resume(), leaving the percpu_ref in a killed state permanently. Fix this by resurrecting the percpu_ref before returning the error, ensuring the page control structure remains usable for subsequent operations.
Affected products (2)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Linux | Linux |
5ab829f1971dc99f2aac10846c378e67fc875abc (affected),
5ab829f1971dc99f2aac10846c378e67fc875abc (affected),
5ab829f1971dc99f2aac10846c378e67fc875abc (affected)
|
— |
| Linux | Linux |
6.18 (affected),
0 (unaffected),
6.18.14 (unaffected),
6.19.4 (unaffected),
7.0 (unaffected)
|
— |
Affected products — CPE 2.3 (1) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendor references (3)
References embedded in the original CVE record by the assigning CNA.
Web references (6)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://git.kernel.org/stable/c/095417d6b669c2dec39a5842ccb94df915f97f54 tenable:git.kernel.org
- https://git.kernel.org/stable/c/2446d099350185caeed19ab2c0270451a97296fb tenable:git.kernel.org
- https://git.kernel.org/stable/c/d119bd2e1643cc023210ff3c6f0657e4f914e71d tenable:git.kernel.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-45955 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-45955 tenable:www.cve.org
- https://www.first.org/epss/ tenable:www.first.org
NVD-tagged references (3)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://git.kernel.org/stable/c/095417d6b669c2dec39a5842ccb94df915f97f54 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/2446d099350185caeed19ab2c0270451a97296fb 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/d119bd2e1643cc023210ff3c6f0657e4f914e71d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
Remediations (18)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:blog.gridinsoft.com
Google says Android CVE -2025-48595 may be under limited targeted exploitation. Check your June 2026 patch level and reduce APK risk.
2026-06-04 00:15 UTC -
web:iplogger.org
Proactive Mitigation Strategies and Incident Response For individuals and enterprises alike, immediate action is crucial: Timely Patch Deployment: Users should update their Android devices as soon as the June 2026 security patch becomes available for their specific device model and carrier.
2026-06-04 00:15 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-04 00:15 UTC -
web:socradar.io
Google's June 2026 Android Security Bulletin includes a fix for an Android Framework elevation of privilege zero-day tracked as CVE -2025-48595. Google noted the issue "may be under limited, targeted exploitation," which raises the priority for teams managing Android fleets. The bulletin ships two patch levels, 2026 -06-01 and 2026 -06-05, with the latter bundling additional partner, device ...
2026-06-04 00:15 UTC -
web:source.android.com
Android partners are encouraged to fix all issues in this bulletin and use the latest security patch level. Devices that use the 2025-08-01 security patch level must include all issues associated with that security patch level, as well as fixes for all issues reported in previous security bulletins.
2026-06-04 00:15 UTC -
web:thecyberexpress.com
Google's June 2026 Android update patches 124 flaws, including exploited zero-day CVE -2025-48595 affecting Android 14, 15 and 16.
2026-06-04 00:15 UTC -
web:www.helpnetsecurity.com
Google's June 2026 Android security updates fix many vulnerabilities, including CVE -2025-48595, which is exploited in targeted attacks.
2026-06-04 00:15 UTC -
web:www.it-connect.tech
Google's June 2026 Android patches fix 124 flaws, including an actively exploited zero-day. Learn what's affected and what to do next.
2026-06-04 00:15 UTC -
web:www.levelblue.com
At the time of writing, no patch is available, and no CVE has been assigned. Microsoft has since assigned CVE - 2026 -45585 to this issue and released official mitigation guidance, with a security update pending. The vulnerability is classified as a BitLocker Security Feature Bypass requiring physical access.
2026-06-04 00:15 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-06-04 00:15 UTC -
web:cybersecuritynews.com
Microsoft has officially acknowledged a critical zero-day vulnerability in Microsoft Defender, publicly dubbed "RoguePlanet," and confirmed it is actively developing a security patch to address the flaw.
2026-06-19 02:27 UTC -
web:cybersecuritynews.com
No patch has been released yet; Microsoft has instead issued a multi-step manual mitigation guide while a formal security update is prepared. Windows BitLocker Security Bypass The vulnerability originates in WinRE's handling of the BootExecute registry value under HKLM\ControlSet001\Control\Session Manager.
2026-06-19 02:27 UTC -
web:dailysecurityreview.com
Microsoft disclosed CVE - 2026 -45585, a Windows zero-day that allows attackers with physical access to bypass BitLocker encryption without the decryption key.
2026-06-19 02:27 UTC -
web:its.wsu.edu
Microsoft has updated the mitigation guidance for CVE - 2026 -45585, a vulnerability involving Windows BitLocker security feature bypass. The update replaces the previously documented manual mitigation steps with a deployment script that reduces exposure while a future security update is in development. The vulnerability impacts a limited set of platforms: Windows 11 versions 26H1, 25H2, and 24H2 ...
2026-06-19 02:27 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-06-19 02:27 UTC -
web:www.bleepingcomputer.com
Microsoft has shared mitigations for YellowKey, a recently disclosed Windows BitLocker zero-day vulnerability that grants access to protected drives.
2026-06-19 02:27 UTC -
web:www.computerworld.com
Microsoft says it is considering a patch for a zero-day vulnerability, dubbed YellowKey, that allows attackers with access to a Windows device to bypass Bitlocker encryption protection and read ...
2026-06-19 02:27 UTC -
web:www.forbes.com
Following the release of a BitLocker zero-day security bypass by a disgruntled hacker, Microsoft has now offered mitigation advice until a patch is available.
2026-06-19 02:27 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-45955.json.
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/md/md-llbitmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "095417d6b669c2dec39a5842ccb94df915f97f54",
"status": "affected",
"version": "5ab829f1971dc99f2aac10846c378e67fc875abc",
"versionType": "git"
},
{
"lessThan": "2446d099350185caeed19ab2c0270451a97296fb",
"status": "affected",
"version": "5ab829f1971dc99f2aac10846c378e67fc875abc",
"versionType": "git"
},
{
"lessThan": "d119bd2e1643cc023210ff3c6f0657e4f914e71d",
"status": "affected",
"version": "5ab829f1971dc99f2aac10846c378e67fc875abc",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/md/md-llbitmap.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.18"
},
{
"lessThan": "6.18",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.14",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "6.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "6.18",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/md-llbitmap: fix percpu_ref not resurrected on suspend timeout\n\nWhen llbitmap_suspend_timeout() times out waiting for percpu_ref to\nbecome zero, it returns -ETIMEDOUT without resurrecting the percpu_ref.\nThe caller (md_llbitmap_daemon_fn) then continues to the next page\nwithout calling llbitmap_resume(), leaving the percpu_ref in a killed\nstate permanently.\n\nFix this by resurrecting the percpu_ref before returning the error,\nensuring the page control structure remains usable for subsequent\noperations."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-27T12:18:10.951Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/095417d6b669c2dec39a5842ccb94df915f97f54"
},
{
"url": "https://git.kernel.org/stable/c/2446d099350185caeed19ab2c0270451a97296fb"
},
{
"url": "https://git.kernel.org/stable/c/d119bd2e1643cc023210ff3c6f0657e4f914e71d"
}
],
"title": "md/md-llbitmap: fix percpu_ref not resurrected on suspend timeout",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-45955",
"datePublished": "2026-05-27T12:18:10.951Z",
"dateReserved": "2026-05-13T15:03:33.088Z",
"dateUpdated": "2026-05-27T12:18:10.951Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}