CVE-2026-72437

Source
https://cve.org/CVERecord?id=CVE-2026-72437
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72437.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72437
Downstream
Published
2026-08-15T05:56:50Z
Modified
2026-08-18T03:30:56Z
Summary
md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry
Details

In the Linux kernel, the following vulnerability has been resolved:

md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry

When a read is retried, raid1_read_request() may be called with a pre-allocated r1_bio. If wait_read_barrier() fails for a REQ_NOWAIT read, the bio is completed and the function returns immediately. In this case the existing r1_bio is leaked.

This fixes a leak of pre-allocated r1_bio structures for retried reads.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72437.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5aa705039c4fca84575539bfa2b8a28454a3d2ca
Fixed
d1eda529a4bf6b866d02755723ee0eb1f037a5ed
Fixed
c66ed3e6371f5dba8f5d8ab810d6683ddc99201e
Fixed
db58075bc9c2ad2731f9c063859b47104bc2e7ef
Fixed
6d92dbd73d19a0622f60352ce9d9379f7a760112
Fixed
c6e6354295845698d2fdfa20b71fc404786f7e93
Fixed
69ad6ce47f9bf2b9fe0ed69b042db993d33bbf12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72437.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.17.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72437.json"