CVE-2026-72420
Race in Linux md/raid5 can cause I/O deadlock and kernel hangs.
Is CVE-2026-72420 being exploited?
Not confirmed. CVE-2026-72420 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.45% probability of exploitation in the next 30 days.
How severe is CVE-2026-72420?
CVE-2026-72420 is rated High. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72420?
Yes. A fix has been recorded for CVE-2026-72420. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72420 affect?
CVE-2026-72420 affects Linux kernel md/raid5 module, Servers using software RAID5 (md). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72420?
Update Linux kernel to the patched release; avoid heavy RAID5 I/O until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Race condition causes wait_on_bit to hang, producing I/O deadlock, kernel thread hang, DoS and potential RAID5 data corruption on affected hosts.
Patch when possible
- affected>= fb642b92c267beeefd352af9bc461eac93a7552c and < 8031b0d02bd221a5f9add4357e291fc2a527b83a
- affected>= fb642b92c267beeefd352af9bc461eac93a7552c and < 4d919c9b770996365806b6c8d701912d52baa306
- affected>= fb642b92c267beeefd352af9bc461eac93a7552c and < d684b72dfbd320623ccaab0779aa841190488e7c
- affected>= fb642b92c267beeefd352af9bc461eac93a7552c and < 55b77337bdd088c77461588e5ec094421b89911b
- affected4.1
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.