{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90401","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.811Z","datePublished":"2026-09-17T16:09:31.556Z","dateUpdated":"2026-09-18T17:55:08.085Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:08.085Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd: remove REQ_NOWAIT support from raid1/10/456\n\nREQ_NOWAIT support in md personalities that can block internally is\nfundamentally incomplete. While reads can avoid some blocking paths,\nwrite requests can still encounter cases where one mirror succeeds while\nanother returns -EAGAIN. At that point md cannot distinguish queue\npressure from a real device failure, so it can neither record a bad\nblock nor safely retry the write without REQ_NOWAIT, leaving mirrors\nwith divergent data.\n\nRather than continue advertising REQ_NOWAIT support for personalities\nthat cannot implement it correctly, remove it from raid1, raid10 and\nraid456. Keep REQ_NOWAIT for linear and raid0, which only remap bios to\ntheir underlying devices; stacked limits will still clear the feature if\nany component device lacks REQ_NOWAIT support."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The REQ_NOWAIT bit that drives the bug is set in blkdev_direct_IO() from IOCB_NOWAIT (pwritev2 RWF_NOWAIT or io_uring io_write() with O_DIRECT) on the md gendisk, then md_submit_bio()->raid1_write_request()/raid10_write_request(). nfsd, ksmbd, nvmet_bdev_execute_rw(), and iSCSI iblock submit ordinary READ/WRITE bios without REQ_NOWAIT, so no protocol message carries the flag.\nAC:L - md_init_stacking_limits() advertised BLK_FEAT_NOWAIT, so member clones kept REQ_NOWAIT and raid1_should_handle_error() ignored their failures. The attacker issues concurrent O_DIRECT nowait writes via io_uring/pwritev2 to fill one member's request queue until it returns BLK_STS_AGAIN while the other mirror completes; no uninfluenced race is required.\nPR:L - blkdev_direct_IO() performs no capable() check. Any process that can open the md node or a stacked dm LV (disk group, container CSI block volume, or a delegated /dev/mdX) can issue RWF_NOWAIT O_DIRECT I/O; init-namespace root is not required.\nUI:N - The attacker opens the md block device themselves and issues pwritev2(RWF_NOWAIT) or io_uring io_write(); no separate victim must mount a filesystem, attach media, or confirm an action.\nS:U - Divergent raid1/raid10 mirrors and skipped WriteErrorSeen/bad-block recording remain inside the host md array. The bug does not escape a VM, bypass an IOMMU, or cross another security authority.\nC:N - raid1_end_write_request() ignore_error only skips WriteErrorSeen and R1BIO_WriteError; it does not read other tenants' data or kernel memory. A failed nowait read forced uptodate in raid1_end_read_request() completes into the attacker's own O_DIRECT buffers.\nI:H - When one raid1/raid10 clone succeeds and another returns BLK_STS_AGAIN, raid1_should_handle_error() sets ignore_error, raid1_end_write_request() still sets R1BIO_Uptodate, and raid_end_bio_io() reports success while mirrors hold different data and real member failures are not recorded as bad blocks.\nA:H - raid5 make_discard_request() returned without bio_endio() on REQ_NOWAIT, hanging the discard bio. Ignored member failures also leave a disk In_sync after a nowait EAGAIN, so a later loss of the up-to-date mirror makes diverged sectors unrecoverable and can take the array/filesystem offline."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/md/md-bitmap.c","drivers/md/md-bitmap.h","drivers/md/md-linear.c","drivers/md/md-llbitmap.c","drivers/md/md.c","drivers/md/raid0.c","drivers/md/raid1-10.c","drivers/md/raid1.c","drivers/md/raid10.c","drivers/md/raid5.c"],"versions":[{"version":"f51d46d0e7cb5b8494aa534d276a9d8915a2443d","lessThan":"9bb9504e2d8f3d22ef12d51c333dd499f402dc8f","status":"affected","versionType":"git"},{"version":"f51d46d0e7cb5b8494aa534d276a9d8915a2443d","lessThan":"3fe5b7c9fb72ccc29bfd0f955b124892af7e3674","status":"affected","versionType":"git"},{"version":"39db562b3fedb93978a7e42dd216b306740959f8","status":"affected","versionType":"git"},{"version":"5.15.111","lessThan":"5.16","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/md/md-bitmap.c","drivers/md/md-bitmap.h","drivers/md/md-linear.c","drivers/md/md-llbitmap.c","drivers/md/md.c","drivers/md/raid0.c","drivers/md/raid1-10.c","drivers/md/raid1.c","drivers/md/raid10.c","drivers/md/raid5.c"],"versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.111"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9bb9504e2d8f3d22ef12d51c333dd499f402dc8f"},{"url":"https://git.kernel.org/stable/c/3fe5b7c9fb72ccc29bfd0f955b124892af7e3674"}],"title":"md: remove REQ_NOWAIT support from raid1/10/456","x_generator":{"engine":"bippy-1.2.0"}}}}