{"id":"CVE-2026-72420","summary":"md/raid5: avoid R5_Overlap races while breaking stripe batches","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid5: avoid R5_Overlap races while breaking stripe batches\n\nKCSAN report a race in break_stripe_batch_list() vs. raid5_make_request()\non sh-\u003edev[i].flags (plain word write vs. atomic bit op)..\n\nand .. one possible scenario is:\n\nCPU1                            CPU2\nbreak_stripe_batch_list(sh1)\n-\u003e handle sh2\n-\u003e lock(sh2)\n-\u003e sh2-\u003ebatch_head = NULL\n-\u003e unlock(sh2)\n-\u003e test_and_clear_bit(R5_Overlap, sh2-\u003edev[i].flags)\n-\u003e wake_up_bit(sh2-\u003edev[i].flags)\n                                raid5_make_request()\n                                -\u003e add_all_stripe_bios(sh2)\n                                -\u003e lock(sh2)\n                                -\u003e stripe_bio_overlaps(sh2) returns true\n\t\t\t\t   batch_head is NULL, so new bio overlap\n\t\t\t\t   exist bio on sh2 -\u003e true\n                                -\u003e set_bit(R5_Overlap, sh2-\u003edev[i].flags)\n                                -\u003e unlock(sh2)\n                                -\u003e wait_on_bit(sh2-\u003edev[i].flags)\n-\u003e sh2-\u003edev[i].flags = sh1-\u003edev[i].flags & ~R5_Overlap\n\nNo wait_up_bit(), CPU2 could be wait_on_bit() forever...\n\nFix by :\n- Expand the protect zone.\n- Use batch_head's device flag's snaphot when no held head_sh-\u003estripe_lock.\n- Move sh/head_sh-\u003ebatch_head = NULL to the end of protected zone , and ,\n  any concurrent add_all_stripe_bios() grabs sh-\u003estripe_lock now either:\n\t- see batch_head != null, and , is rejected by stripe_bio_overlaps()\n\t  under the lock (no R5_Overlap wait ) , or ,\n\t- sees batch_head == NULL, only after dev[i].flags has already been\n\t  set and the prior R5_Overlap waiters worken.\n\nKCSAN report:\n================================================\n  BUG: KCSAN: data-race in break_stripe_batch_list / raid5_make_request\n\n  write (marked) to 0xffff8e89c8117548 of 8 bytes by task 4042 on cpu 0:\n    raid5_make_request+0xea0/0x2930\n    md_handle_request+0x4a2/0xa40\n    md_submit_bio+0x109/0x1a0\n    __submit_bio+0x2ec/0x390\n    submit_bio_noacct_nocheck+0x457/0x710\n    submit_bio_noacct+0x2a7/0xc20\n    submit_bio+0x56/0x250\n    blkdev_direct_IO+0x54c/0xda0\n    blkdev_write_iter+0x38f/0x570\n    aio_write+0x22b/0x490\n    io_submit_one+0xa51/0xf70\n    __x64_sys_io_submit+0xf7/0x220\n    x64_sys_call+0x1907/0x1c60\n    do_syscall_64+0x130/0x570\n    entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n  read to 0xffff8e89c8117548 of 8 bytes by task 4010 on cpu 5:\n    break_stripe_batch_list+0x249/0x480\n    handle_stripe_clean_event+0x720/0x9b0\n    handle_stripe+0x32fb/0x4500\n    handle_active_stripes.isra.0+0x6e0/0xa50\n    raid5d+0x7e0/0xba0\n    md_thread+0x15a/0x2d0\n    kthread+0x1e3/0x220\n    ret_from_fork+0x37a/0x410\n    ret_from_fork_asm+0x1a/0x30\n\n  value changed: 0x0000000000000019 -\u003e 0x0000000000000099 --\u003e R5_Overlap","modified":"2026-08-18T03:56:43.129565595Z","published":"2026-08-15T05:56:39.802Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72420.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/4d919c9b770996365806b6c8d701912d52baa306"},{"type":"WEB","url":"https://git.kernel.org/stable/c/55b77337bdd088c77461588e5ec094421b89911b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8031b0d02bd221a5f9add4357e291fc2a527b83a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d684b72dfbd320623ccaab0779aa841190488e7c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72420.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72420"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"fb642b92c267beeefd352af9bc461eac93a7552c"},{"fixed":"8031b0d02bd221a5f9add4357e291fc2a527b83a"},{"fixed":"4d919c9b770996365806b6c8d701912d52baa306"},{"fixed":"d684b72dfbd320623ccaab0779aa841190488e7c"},{"fixed":"55b77337bdd088c77461588e5ec094421b89911b"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72420.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"6.12.97"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.40"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72420.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}