Answer in brief
CVE-2026-74372 records a Unknown severity vulnerability in raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f2a38abf5f1c5aeb3be8e9f4d3d815c867fff7ca <5ac9e793ba2583d72740d929e7858a6c82e22ed5 || >=f2a38abf5f1c5aeb3be8e9f4d3d815c867fff7ca <731485617bf862f1289c3f40ed1f800d0475826f || >=f2a38abf5f1c5aeb3be8e9f4d3d815c867fff7ca <909d9dc3b5730c8ed7b764c68bc788342df2a07b | 5ac9e793ba2583d72740d929e7858a6c82e22ed5, 731485617bf862f1289c3f40ed1f800d0475826f, 909d9dc3b5730c8ed7b764c68bc788342df2a07b |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path In raid1_write_request(), each per-mirror loop iteration begins by incrementing rdev->nr_pending. If a REQ_ATOMIC write encounters a badblock within the requested range, the code jumps to err_handle without dropping the reference taken for the current mirror. err_handle's cleanup loop will only decrements for k < i and r1_bio->bios[k] is non-NULL. The current slot is therefore skipped, leaving its nr_pending reference leaked permanently. The reference prevents the rdev from ever being removed, since raid1_remove_conf() refuses to remove an rdev with nr_pending > 0. Fix this by calling rdev_dec_pending() before jumping to err_handle.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-74372 records a Unknown severity vulnerability in raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f2a38abf5f1c5aeb3be8e9f4d3d815c867fff7ca <5ac9e793ba2583d72740d929e7858a6c82e22ed5 || >=f2a38abf5f1c5aeb3be8e9f4d3d815c867fff7ca <731485617bf862f1289c3f40ed1f800d0475826f || >=f2a38abf5f1c5aeb3be8e9f4d3d815c867fff7ca <909d9dc3b5730c8ed7b764c68bc788342df2a07b | 5ac9e793ba2583d72740d929e7858a6c82e22ed5, 731485617bf862f1289c3f40ed1f800d0475826f, 909d9dc3b5730c8ed7b764c68bc788342df2a07b |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path In raid1_write_request(), each per-mirror loop iteration begins by incrementing rdev->nr_pending. If a REQ_ATOMIC write encounters a badblock within the requested range, the code jumps to err_handle without dropping the reference taken for the current mirror. err_handle's cleanup loop will only decrements for k < i and r1_bio->bios[k] is non-NULL. The current slot is therefore skipped, leaving its nr_pending reference leaked permanently. The reference prevents the rdev from ever being removed, since raid1_remove_conf() refuses to remove an rdev with nr_pending > 0. Fix this by calling rdev_dec_pending() before jumping to err_handle.
Quoted source text, attributed separately from HOL analysis.