CVE-2026-72437

high

Description

In the Linux kernel, the following vulnerability has been resolved: md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry When a read is retried, raid1_read_request() may be called with a pre-allocated r1_bio. If wait_read_barrier() fails for a REQ_NOWAIT read, the bio is completed and the function returns immediately. In this case the existing r1_bio is leaked. This fixes a leak of pre-allocated r1_bio structures for retried reads.

References

https://git.kernel.org/stable/c/db58075bc9c2ad2731f9c063859b47104bc2e7ef

https://git.kernel.org/stable/c/d1eda529a4bf6b866d02755723ee0eb1f037a5ed

https://git.kernel.org/stable/c/c6e6354295845698d2fdfa20b71fc404786f7e93

https://git.kernel.org/stable/c/c66ed3e6371f5dba8f5d8ab810d6683ddc99201e

https://git.kernel.org/stable/c/6d92dbd73d19a0622f60352ce9d9379f7a760112

https://git.kernel.org/stable/c/69ad6ce47f9bf2b9fe0ed69b042db993d33bbf12

Details

Source: Mitre, NVD

Published: 2026-08-15

Updated: 2026-08-17

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.00215