Description
In the Linux kernel, the following vulnerability has been resolved:

md/raid10: fix writes_pending and barrier reference leaks on discard failures

raid10_make_request() acquires a writes_pending reference with
md_write_start() before calling raid10_handle_discard(). Several failure
paths in raid10_handle_discard() complete the bio and return without
releasing the corresponding reference, causing md_write_end() to be
skipped.

Call md_write_end() before returning from these failure paths to keep
writes_pending accounting balanced.

Additionally, discard split allocation failures can occur after
wait_barrier() succeeds. Those paths return without calling
allow_barrier(), leaking the associated barrier reference.

Release the barrier before returning from those paths.
Published: 2026-08-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel’s RAID10 subsystem contains a reference‑counting flaw that causes writes_pending and barrier references to leak when a discard operation fails. The bug manifests because md_write_end() and allow_barrier() are omitted on certain error paths, leading to unbalanced accounting. Based on the description, it is inferred that the leak could increase resource usage over time, potentially degrading system performance or destabilizing the kernel.

Affected Systems

All Linux kernel builds that do not incorporate commits 393d687131d8aa8c7e4de2cb494438e145d20fc2 and d1324b41dabd26787559efaeb430643c627c1eb0 are vulnerable. The issue appears in RAID10 configurations before these patches and is resolved in kernel releases that include the cited commits.

Risk and Exploitability

The CVSS score of 7.5 reflects a high‑impact resource‑exhaustion vulnerability. The EPSS score of <1% indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV, implying no confirmed active exploitation. The attack vector is likely a failed discard request on a RAID10 device; this inference is based on the failure paths that trigger the reference leak.

Generated by OpenCVE AI on August 18, 2026 at 14:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a kernel version that includes commits 393d687131d8aa8c7e4de2cb494438e145d20fc2 and d1324b41dabd26787559efaeb430643c627c1eb0
  • Reboot the system so the patched kernel image is loaded
  • If discard operations are not required, disable discard requests for affected RAID10 devices to mitigate the risk while a patch is pending

Generated by OpenCVE AI on August 18, 2026 at 14:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-675

Mon, 17 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-778

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 15 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-778

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix writes_pending and barrier reference leaks on discard failures raid10_make_request() acquires a writes_pending reference with md_write_start() before calling raid10_handle_discard(). Several failure paths in raid10_handle_discard() complete the bio and return without releasing the corresponding reference, causing md_write_end() to be skipped. Call md_write_end() before returning from these failure paths to keep writes_pending accounting balanced. Additionally, discard split allocation failures can occur after wait_barrier() succeeds. Those paths return without calling allow_barrier(), leaking the associated barrier reference. Release the barrier before returning from those paths.
Title md/raid10: fix writes_pending and barrier reference leaks on discard failures
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:44:13.101Z

Reserved: 2026-08-09T03:40:39.929Z

Link: CVE-2026-72438

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:17.660

Modified: 2026-08-17T06:19:11.180

Link: CVE-2026-72438

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72438 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T14:30:05Z

Weaknesses
  • CWE-675

    Multiple Operations on Resource in Single-Operation Context

  • CWE-772

    Missing Release of Resource after Effective Lifetime