PatchSiren cyber security CVE debrief
CVE-2026-72420 Linux CVE debrief
A race condition vulnerability was found in the Linux kernel's md/raid5 implementation. The issue occurs in the break_stripe_batch_list() and raid5_make_request() functions, which can lead to a deadlock situation. The vulnerability has been resolved by expanding the protect zone, using batch_head's device flag's snapshot when no held head_sh->stripe_lock, and moving sh/head_sh->batch_head = NULL to the end of the protected zone.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel developers and administrators who use md/raid5 implementation
Technical summary
The vulnerability is caused by a data race in break_stripe_batch_list / raid5_make_request, which can lead to a deadlock situation. The issue is related to a plain word write vs. atomic bit op on sh->dev[i].flags. The fix involves expanding the protect zone and using batch_head's device flag's snapshot when no held head_sh->stripe_lock.
Defensive priority
Medium
Recommended defensive actions
- Apply the kernel patch to fix the vulnerability
- Review and update md/raid5 implementation to prevent similar issues
- Monitor system logs for potential exploitation attempts
Evidence notes
The vulnerability was reported by KCSAN and is related to a data race in break_stripe_batch_list / raid5_make_request. The issue is caused by a plain word write vs. atomic bit op on sh->dev[i].flags. The fix involves expanding the protect zone and using batch_head's device flag's snapshot when no held head_sh->stripe_lock.
Official resources
-
CVE-2026-72420 CVE record
CVE.org
-
CVE-2026-72420 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T06:22:15.743Z and has not been modified since then.