Executive brief
The Linux kernel's RAID management subsystem (md) advertised support for non-blocking I/O (REQ_NOWAIT) in RAID1, RAID10, and RAID456 configurations, but could not implement it correctly. When write requests encountered certain failure scenarios, the system could not distinguish between temporary queue pressure and actual device failures, resulting in inconsistent data across mirror copies. This fix removes the non-blocking I/O capability from these RAID types to prevent silent data divergence.
Technical details
The vulnerability exists in the md RAID driver's handling of REQ_NOWAIT (non-blocking I/O requests). Specifically, RAID personalities that can block internally (RAID1, RAID10, RAID456) cannot correctly handle cases where one mirror succeeds while another returns -EAGAIN. The kernel cannot distinguish queue pressure from device failure in these cases, preventing proper bad block recording or safe retry logic without REQ_NOWAIT, leaving mirrors with divergent data. The fix removes REQ_NOWAIT advertising from raid1, raid10, and raid456 while retaining it for raid0 and linear, which only remap I/O to underlying devices without blocking logic. No patch bypasses or workarounds are known; the mitigation is removal of the incomplete feature.
Affected products
- Linux Linux kernel Multiple versions with md RAID REQ_NOWAIT support
Timeline
- 2026-09-17: disclosed: CVE-2026-90401 published
- 2026-06-28: patched: Fix committed (3fe5b7c9fb72ccc29bfd0f955b124892af7e3674)