CVE-2026-45888: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: md/raid1: fix memory leak in raid1_run() raid1_run() calls setup_conf() which registers a thread via md_register_thread(). If raid1_set_limits() fails, the previously registered thread is not unregistered, resulting in a memory leak of the md_thread structure and the thread resource itself. Add md_unregister_thread() to the error path to properly cleanup the thread, which aligns with the error handling logic of other paths in this function. Compile tested only. Issue found using a prototype static analysis tool and code review.

Affected products

  • Linux Linux Kernel: from 6.9, before 6.12.75 (fixed in 6.12.75); from 6.13, before 6.18.14 (fixed in 6.18.14); from 6.19, before 6.19.4 (fixed in 6.19.4)

Published 2026-05-27. Last modified 2026-06-25.