Junglewise Threat Intelligence

CVE-2026-72437: Linux kernel md/raid1 r1_bio memory leak with REQ_NOWAIT

CVE-2026-72437 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RAID1 storage management code has a memory leak in the read request handling path. When a read operation is retried with the non-blocking I/O flag set, pre-allocated data structures may not be properly freed before the function returns, causing memory to accumulate over time. This can gradually degrade system performance and potentially lead to out-of-memory conditions on systems using RAID1 with frequent retried I/O operations.

Technical details

A memory leak exists in the raid1_read_request() function in drivers/md/raid1.c. When a retried read request has the REQ_NOWAIT flag set and the wait_read_barrier() function fails, the bio is completed and the function returns without properly freeing a pre-allocated r1_bio structure. The vulnerability occurs because the error path does not check if r1_bio_existed is true before returning; if true, the r1_bio should be marked as returned and passed to raid_end_bio_io() for proper cleanup. This is a local memory leak affecting only systems using md/raid1 with non-blocking I/O patterns. The fix adds explicit cleanup code to free the structure when this condition is encountered.

Affected products

  • Linux Linux kernel all versions with md raid1 nowait support (5.x and later)

Timeline

  • 2026-08-15: disclosed
  • 2026-06-21: patched

References

Related threats