{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.5-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  md/raid5: avoid R5_Overlap races while breaking stripe batches  KCSAN report a race in break_stripe_batch_list() vs. raid5_make_request() on sh-\u003edev[i].flags (plain word write vs. atomic bit op)..  and .. one possible scenario is:  CPU1                            CPU2 break_stripe_batch_list(sh1) -\u003e handle sh2 -\u003e lock(sh2) -\u003e sh2-\u003ebatch_head = NULL -\u003e unlock(sh2) -\u003e test_and_clear_bit(R5_Overlap, sh2-\u003edev[i].flags) -\u003e wake_up_bit(sh2-\u003edev[i].flags)                                 raid5_make_request()                                 -\u003e add_all_stripe_bios(sh2)                                 -\u003e lock(sh2)                                 -\u003e stripe_bio_overlaps(sh2) returns true \t\t\t\t   batch_head is NULL, so new bio overlap \t\t\t\t   exist bio on sh2 -\u003e true                                 -\u003e set_bit(R5_Overlap, sh2-\u003edev[i].flags)                                 -\u003e unlock(sh2)                                 -\u003e wait_on_bit(sh2-\u003edev[i].flags) -\u003e sh2-\u003edev[i].flags = sh1-\u003edev[i].flags \u0026 ~R5_Overlap  No wait_up_bit(), CPU2 could be wait_on_bit() forever...  Fix by : - Expand the protect zone. - Use batch_head's device flag's snaphot when no held head_sh-\u003estripe_lock. - Move sh/head_sh-\u003ebatch_head = NULL to the end of protected zone , and ,   any concurrent add_all_stripe_bios() grabs sh-\u003estripe_lock now either: \t- see batch_head != null, and , is rejected by stripe_bio_overlaps() \t  under the lock (no R5_Overlap wait ) , or , \t- sees batch_head == NULL, only after dev[i].flags has already been \t  set and the prior R5_Overlap waiters worken.  KCSAN report: ================================================   BUG: KCSAN: data-race in break_stripe_batch_list / raid5_make_request    write (marked) to 0xffff8e89c8117548 of 8 bytes by task 4042 on cpu 0:     raid5_make_request+0xea0/0x2930     md_handle_request+0x4a2/0xa40     md_submit_bio+0x109/0x1a0     __submit_bio+0x2ec/0x390     submit_bio_noacct_nocheck+0x457/0x710     submit_bio_noacct+0x2a7/0xc20     submit_bio+0x56/0x250     blkdev_direct_IO+0x54c/0xda0     blkdev_write_iter+0x38f/0x570     aio_write+0x22b/0x490     io_submit_one+0xa51/0xf70     __x64_sys_io_submit+0xf7/0x220     x64_sys_call+0x1907/0x1c60     do_syscall_64+0x130/0x570     entry_SYSCALL_64_after_hwframe+0x76/0x7e    read to 0xffff8e89c8117548 of 8 bytes by task 4010 on cpu 5:     break_stripe_batch_list+0x249/0x480     handle_stripe_clean_event+0x720/0x9b0     handle_stripe+0x32fb/0x4500     handle_active_stripes.isra.0+0x6e0/0xa50     raid5d+0x7e0/0xba0     md_thread+0x15a/0x2d0     kthread+0x1e3/0x220     ret_from_fork+0x37a/0x410     ret_from_fork_asm+0x1a/0x30    value changed: 0x0000000000000019 -\u003e 0x0000000000000099 --\u003e R5_Overlap",
  "id": "DEBIAN-CVE-2026-72420",
  "modified": "2026-09-14T16:47:48.761519685Z",
  "published": "2026-08-15T06:22:15.743Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-72420"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-72420"
  ]
}