AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72440

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's RAID1 implementation, specifically in the handling of write requests where certain failure paths can lead to reference leaks for both writes_pending and barrier references. This can result in resource exhaustion or inconsistent state within the RAID subsystem, potentially impacting data integrity and system stability. Organizations using Linux systems with RAID1 configurations should prioritize addressing this issue to ensure robust data management and prevent potential system failures.

CVE
CVE-2026-72440
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: md/raid1: fix writes_pending and barrier reference leaks on write failures raid1_make_request() acquires a writes_pending reference with md_write_start() before calling raid1_write_request(). Several failure paths in raid1_write_request() complete the bio and return without reaching the normal write completion path, causing the corresponding md_write_end() to be skipped. Make raid1_write_request() return a status indicating whether the write request was successfully queued. This allows raid1_make_request() to call md_write_end() when raid1_write_request() fails. Additionally, if wait_blocked_rdev() fails after wait_barrier() succeeds, the associated barrier reference is not released. Call allow_barrier() before returning from that path to keep the barrier accounting balanced.