๐Ÿ” CVE Alert

CVE-2026-63804

UNKNOWN 0.0

gfs2: fix use-after-free in gfs2_qd_dealloc

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: gfs2: fix use-after-free in gfs2_qd_dealloc gfs2_qd_dealloc(), called as an RCU callback from gfs2_qd_dispose(), accesses the superblock object sdp through qd->qd_sbd after freeing qd. It does so to decrement sd_quota_count and wake up sd_kill_wait. However, by the time the RCU callback runs, gfs2_put_super() may have already freed sdp via free_sbd(). This can happen when gfs2_quota_cleanup() is called during unmount: it disposes of quota objects via call_rcu() and then waits on sd_kill_wait with a 60-second timeout. If the timeout expires, or if gfs2_gl_hash_clear() triggers additional qd_put() calls that schedule more RCU callbacks after the wait completes, gfs2_put_super() will proceed to free the superblock while RCU callbacks referencing it are still pending. Add an rcu_barrier() before free_sbd() in gfs2_put_super() to ensure all pending RCU callbacks (including gfs2_qd_dealloc) have completed before the superblock is freed.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
a475c5dd16e57c570113eccba51955b5df8bb052 < 4fe388218826df8607ae41a6305df67db08a9093 a475c5dd16e57c570113eccba51955b5df8bb052 < 8745d9f7e1682c39f0a1578895ac74205e2a6757 a475c5dd16e57c570113eccba51955b5df8bb052 < b85ef03f726b15047a6fa6d11b639bdf6c0ee4f0 a475c5dd16e57c570113eccba51955b5df8bb052 < 9d0d5ba20cad661f7f287d4c66d2c19022ce2fd0 a475c5dd16e57c570113eccba51955b5df8bb052 < f9c9ec2c319f843b70ecdf939d48b52d189bc081
Linux / Linux
6.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/4fe388218826df8607ae41a6305df67db08a9093 git.kernel.org: https://git.kernel.org/stable/c/8745d9f7e1682c39f0a1578895ac74205e2a6757 git.kernel.org: https://git.kernel.org/stable/c/b85ef03f726b15047a6fa6d11b639bdf6c0ee4f0 git.kernel.org: https://git.kernel.org/stable/c/9d0d5ba20cad661f7f287d4c66d2c19022ce2fd0 git.kernel.org: https://git.kernel.org/stable/c/f9c9ec2c319f843b70ecdf939d48b52d189bc081