ThreatCluster

Microsoft Addresses Deadlock and BUG_ON Issues in RAID5 with CVEs

First seen 18 Feb 2026, 12:23 UTC Api.Msrc.Microsoft 39

Article Content

Browse articles
ThreatCluster

Microsoft has published two critical updates addressing vulnerabilities in the md/raid5 subsystem. CVE-2024-39476, published on July 5, 2024, resolves a deadlock issue where raid5d() could wait for itself to clear a pending state. CVE-2024-43914, published on August 26, 2024, prevents a BUG_ON() condition during reshape operations after reassembling.

Timeline

2024-07-05
CVE-2024-39476 published
2024-08-26
CVE-2024-43914 published
2026-02-18
Two articles published addressing RAID5 vulnerabilities