{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-72440","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-09T03:40:39.930Z","datePublished":"2026-08-15T05:56:52.662Z","dateUpdated":"2026-08-17T05:44:14.243Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:44:14.243Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid1: fix writes_pending and barrier reference leaks on write failures\n\nraid1_make_request() acquires a writes_pending reference with\nmd_write_start() before calling raid1_write_request(). Several failure\npaths in raid1_write_request() complete the bio and return without\nreaching the normal write completion path, causing the corresponding\nmd_write_end() to be skipped.\n\nMake raid1_write_request() return a status indicating whether the write\nrequest was successfully queued. This allows raid1_make_request() to\ncall md_write_end() when raid1_write_request() fails.\n\nAdditionally, if wait_blocked_rdev() fails after wait_barrier()\nsucceeds, the associated barrier reference is not released.\n\nCall allow_barrier() before returning from that path to keep the barrier\naccounting balanced."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The bug is in md/raid1 write handling reached via block-layer writes to RAID1-backed volumes; on storage servers and appliances, remote NFS, SMB (ksmbd), iSCSI, and NVMe-oF clients submit those writes through md_submit_bio() to raid1_make_request() the same as local I/O.\nAC:L - An attacker with write access can reliably trigger the leaks using RWF_NOWAIT during active resync/barriers, against mirrors in BlockedBadBlocks state after prior write errors, or via bio_submit_split_bioset() failure paths; they control I/O timing and concurrency without uncontrollable races.\nPR:L - Exploitation requires only the ability to issue writes to the RAID1 array—via a mounted filesystem, O_RDWR on /dev/mdX, or an authenticated network storage client—not CAP_SYS_ADMIN or other privileges needed to create or reconfigure the md array.\nUI:N - No victim interaction is required; the attacker or their storage client issues the triggering RWF_NOWAIT or failing write requests directly, with no separate mount, file open, or administrator action needed at exploitation time.\nS:U - Impact is confined to kernel md RAID1 write/barrier accounting and array lifecycle state within the same host kernel; it does not cross VM, container, or IOMMU security boundaries.\nC:N - Leaked writes_pending and nr_pending reference counters do not corrupt memory, read out of bounds, or use-after-free; there is no kernel pointer leak or arbitrary memory disclosure primitive.\nI:L - Skipped md_write_end() on failure paths leaves writes_pending inflated and prevents set_in_sync()/clean sysfs transitions, causing persistent incorrect RAID1 dirty/clean metadata state that cannot be corrected until reboot.\nA:H - Leaked conf->nr_pending from the wait_blocked_rdev()+REQ_NOWAIT path inflates get_unqueued_pending() so freeze_array() wait_event never completes, deadlocking array quiesce, reshape, removal, and read-error recovery while array_frozen blocks new I/O."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/md/raid1.c"],"versions":[{"version":"5aa705039c4fca84575539bfa2b8a28454a3d2ca","lessThan":"bffbbfcbd9393e315a7a4286dcd70e875265db9a","status":"affected","versionType":"git"},{"version":"5aa705039c4fca84575539bfa2b8a28454a3d2ca","lessThan":"8e065a1602511282fc0da2dc89445e0eb71a681c","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/md/raid1.c"],"versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/bffbbfcbd9393e315a7a4286dcd70e875265db9a"},{"url":"https://git.kernel.org/stable/c/8e065a1602511282fc0da2dc89445e0eb71a681c"}],"title":"md/raid1: fix writes_pending and barrier reference leaks on write failures","x_generator":{"engine":"bippy-1.2.0"}}}}