Answer in brief
CVE-2026-72438 records a High severity (CVSS 7.5) vulnerability in md/raid10: fix writes_pending and barrier reference leaks on discard failures. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c9aa889b035fca4598ae985a0f0c76ebbb547ad2 <d1324b41dabd26787559efaeb430643c627c1eb0 || >=c9aa889b035fca4598ae985a0f0c76ebbb547ad2 <393d687131d8aa8c7e4de2cb494438e145d20fc2 || 39db562b3fedb93978a7e42dd216b306740959f8 || >=5.15.111 <5.16 | d1324b41dabd26787559efaeb430643c627c1eb0, 393d687131d8aa8c7e4de2cb494438e145d20fc2, 5.16 |
| Linux/Linuxgeneric | 5.17 | Not reported |
| Linux/Linuxgeneric | >=c9aa889b035fca4598ae985a0f0c76ebbb547ad2 <fea33968592559a55a3f5a96a6386bebcaf988a8 || >=c9aa889b035fca4598ae985a0f0c76ebbb547ad2 <11b35d1906a7277a3d64afe34224133b44327328 || >=c9aa889b035fca4598ae985a0f0c76ebbb547ad2 <d1324b41dabd26787559efaeb430643c627c1eb0 || >=c9aa889b035fca4598ae985a0f0c76ebbb547ad2 <393d687131d8aa8c7e4de2cb494438e145d20fc2 || 39db562b3fedb93978a7e42dd216b306740959f8 || >=5.15.111 <5.16 | fea33968592559a55a3f5a96a6386bebcaf988a8, 11b35d1906a7277a3d64afe34224133b44327328, d1324b41dabd26787559efaeb430643c627c1eb0, 393d687131d8aa8c7e4de2cb494438e145d20fc2, 5.16 |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 21, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix writes_pending and barrier reference leaks on discard failures raid10_make_request() acquires a writes_pending reference with md_write_start() before calling raid10_handle_discard(). Several failure paths in raid10_handle_discard() complete the bio and return without releasing the corresponding reference, causing md_write_end() to be skipped. Call md_write_end() before returning from these failure paths to keep writes_pending accounting balanced. Additionally, discard split allocation failures can occur after wait_barrier() succeeds. Those paths return without calling allow_barrier(), leaking the associated barrier reference. Release the barrier before returning from those paths.
Quoted source text, attributed separately from HOL analysis.