CVE-2026-90401

Summary

In the Linux kernel, the following vulnerability has been resolved:

md: remove REQ_NOWAIT support from raid1/10/456

REQ_NOWAIT support in md personalities that can block internally is fundamentally incomplete. While reads can avoid some blocking paths, write requests can still encounter cases where one mirror succeeds while another returns -EAGAIN. At that point md cannot distinguish queue pressure from a real device failure, so it can neither record a bad block nor safely retry the write without REQ_NOWAIT, leaving mirrors with divergent data.

Rather than continue advertising REQ_NOWAIT support for personalities that cannot implement it correctly, remove it from raid1, raid10 and raid456. Keep REQ_NOWAIT for linear and raid0, which only remap bios to their underlying devices; stacked limits will still clear the feature if any component device lacks REQ_NOWAIT support.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxf51d46d0e7cb5b8494aa534d276a9d8915a2443d < 9bb9504e2d8f3d22ef12d51c333dd499f402dc8faffected
LinuxLinuxf51d46d0e7cb5b8494aa534d276a9d8915a2443d < 3fe5b7c9fb72ccc29bfd0f955b124892af7e3674affected
LinuxLinux39db562b3fedb93978a7e42dd216b306740959f8affected
LinuxLinux5.15.111 < 5.16affected
LinuxLinux5.17affected
LinuxLinux0 < 5.17unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References