Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-90401NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

md: remove REQ_NOWAIT support from raid1/10/456

REQ_NOWAIT support in md personalities that can block internally is
fundamentally incomplete. While reads can avoid some blocking paths,
write requests can still encounter cases where one mirror succeeds while
another returns -EAGAIN. At that point md cannot distinguish queue
pressure from a real device failure, so it can neither record a bad
block nor safely retry the write without REQ_NOWAIT, leaving mirrors
with divergent data.

Rather than continue advertising REQ_NOWAIT support for personalities
that cannot implement it correctly, remove it from raid1, raid10 and
raid456. Keep REQ_NOWAIT for linear and raid0, which only remap bios to
their underlying devices; stacked limits will still clear the feature if
any component device lacks REQ_NOWAIT support.
Severity Level
HIGH(7.1)
Published Date
Sep 17, 2026
Last Modified
Sep 18, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.11%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics — Score 7.1 (HIGH)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityHigh
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • Linux Linux >= f51d46d0e7cb5b8494aa534d276a9d8915a2443d and < 9bb9504e2d8f3d22ef12d51c333dd499f402dc8f
  • Linux Linux >= f51d46d0e7cb5b8494aa534d276a9d8915a2443d and < 3fe5b7c9fb72ccc29bfd0f955b124892af7e3674
  • Linux Linux >= 39db562b3fedb93978a7e42dd216b306740959f8
  • Linux Linux >= 5.15.111 and < 5.16
  • Linux Linux >= 5.17
Patched Versions
  • Linux Linux 9bb9504e2d8f3d22ef12d51c333dd499f402dc8f
  • Linux Linux 3fe5b7c9fb72ccc29bfd0f955b124892af7e3674
  • Linux Linux 5.16
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.