๐Ÿ” CVE Alert

CVE-2026-90326

UNKNOWN 0.0

blk-cgroup: fix race between policy activation and blkg destruction

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix race between policy activation and blkg destruction When switching an IO scheduler on a block device, blkcg_activate_policy() allocates blkg_policy_data (pd) for all blkgs attached to the queue. However, blkcg_activate_policy() may race with concurrent blkcg deletion, leading to use-after-free and memory leak issues. The use-after-free occurs in the following race: T1 (blkcg_activate_policy): - Successfully allocates pd for blkg1 (loop0->queue, blkcgA) - Fails to allocate pd for blkg2 (loop0->queue, blkcgB) - Enters the enomem rollback path to release blkg1 resources T2 (blkcg deletion): - blkcgA is deleted concurrently - blkg1 is freed via blkg_free_workfn() - blkg1->pd is freed T1 (continued): - Rollback path accesses blkg1->pd->online after pd is freed - Triggers use-after-free In addition, blkg_free_workfn() frees pd before removing the blkg from q->blkg_list. This allows blkcg_activate_policy() to allocate a new pd for a blkg that is being destroyed, leaving the newly allocated pd unreachable when the blkg is finally freed. Fix these races by extending blkcg_mutex coverage to serialize blkcg_activate_policy() rollback and blkg destruction, ensuring pd lifecycle is synchronized with blkg list visibility.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
81c1188905f88b77743d1fdeeedfc8cb7b67787d < b5dae1cd0d8368b4338430ff93403df67f0b8bcc bfe46d2efe46c5c952f982e2ca94fe2ec5e58e2a < 083b58373463a6e5ee60ecb135269348f68ad7df f1c006f1c6850c14040f8337753a63119bba39b9 < ac34e655dffa74349d885a43d098115336f53842 f1c006f1c6850c14040f8337753a63119bba39b9 < 2cf9f50a38c1839e549a08e22aa35e8d69e2c8fd f1c006f1c6850c14040f8337753a63119bba39b9 < 5313d4d41739b0cb63000747c97bb1217ac45f3e 6.1.16 < 6.1.17 6.2.3 < 6.2.4
Linux / Linux
6.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/b5dae1cd0d8368b4338430ff93403df67f0b8bcc git.kernel.org: https://git.kernel.org/stable/c/083b58373463a6e5ee60ecb135269348f68ad7df git.kernel.org: https://git.kernel.org/stable/c/ac34e655dffa74349d885a43d098115336f53842 git.kernel.org: https://git.kernel.org/stable/c/2cf9f50a38c1839e549a08e22aa35e8d69e2c8fd git.kernel.org: https://git.kernel.org/stable/c/5313d4d41739b0cb63000747c97bb1217ac45f3e