CVE-2026-72437

UnknownEPSS 0.21%

Last modified

CVE-2026-72437 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry When a read is retried, raid1_read_request() may be called with a pre-allocated r1_bio. If wait_read_barrier() fails for a REQ_NOWAIT read, the bio is completed and the function returns immediately. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry When a read is retried, raid1_read_request() may be called with a pre-allocated r1_bio. If wait_read_barrier() fails for a REQ_NOWAIT read, the bio is completed and the function returns immediately. In this case the existing r1_bio is leaked. This fixes a leak of pre-allocated r1_bio structures for retried reads.

Metrics

EPSS Probability
0.21%

12.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 5aa705039c4fca84575539bfa2b8a28454a3d2ca, < d1eda529a4bf6b866d02755723ee0eb1f037a5ed; >= 5aa705039c4fca84575539bfa2b8a28454a3d2ca, < c66ed3e6371f5dba8f5d8ab810d6683ddc99201e; >= 5aa705039c4fca84575539bfa2b8a28454a3d2ca, < db58075bc9c2ad2731f9c063859b47104bc2e7ef; >= 5aa705039c4fca84575539bfa2b8a28454a3d2ca, < 6d92dbd73d19a0622f60352ce9d9379f7a760112; >= 5aa705039c4fca84575539bfa2b8a28454a3d2ca, < c6e6354295845698d2fdfa20b71fc404786f7e93; >= 5aa705039c4fca84575539bfa2b8a28454a3d2ca, < 69ad6ce47f9bf2b9fe0ed69b042db993d33bbf12
LinuxLinux5.17

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-72437?
In the Linux kernel, the following vulnerability has been resolved: md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry When a read is retried, raid1_read_request() may be called with a pre-allocated r1_bio. If wait_read_barrier() fails for a REQ_NOWAIT read, the bio is completed and the function returns immediately. In this case the existing r1_bio is leaked. This fixes a leak of pre-allocated r1_bio structures for retried reads.
How severe is CVE-2026-72437?
Severity scoring for CVE-2026-72437 is pending analysis. The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-72437?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-72437?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST