Junglewise Threat Intelligence

CVE-2026-90401: Linux kernel md RAID incomplete REQ_NOWAIT blocking

CVE-2026-90401 · Severity: high · CVSS 7.1 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RAID management subsystem (md) advertised support for non-blocking I/O (REQ_NOWAIT) in RAID1, RAID10, and RAID456 configurations, but could not implement it correctly. When write requests encountered certain failure scenarios, the system could not distinguish between temporary queue pressure and actual device failures, resulting in inconsistent data across mirror copies. This fix removes the non-blocking I/O capability from these RAID types to prevent silent data divergence.

Technical details

The vulnerability exists in the md RAID driver's handling of REQ_NOWAIT (non-blocking I/O requests). Specifically, RAID personalities that can block internally (RAID1, RAID10, RAID456) cannot correctly handle cases where one mirror succeeds while another returns -EAGAIN. The kernel cannot distinguish queue pressure from device failure in these cases, preventing proper bad block recording or safe retry logic without REQ_NOWAIT, leaving mirrors with divergent data. The fix removes REQ_NOWAIT advertising from raid1, raid10, and raid456 while retaining it for raid0 and linear, which only remap I/O to underlying devices without blocking logic. No patch bypasses or workarounds are known; the mitigation is removal of the incomplete feature.

Affected products

  • Linux Linux kernel Multiple versions with md RAID REQ_NOWAIT support

Timeline

  • 2026-09-17: disclosed: CVE-2026-90401 published
  • 2026-06-28: patched: Fix committed (3fe5b7c9fb72ccc29bfd0f955b124892af7e3674)

References

Related threats