7.8

CVE-2026-90326

blk-cgroup: fix race between policy activation and blkg destruction

In the Linux kernel, the following vulnerability has been resolved:

blk-cgroup: fix race between policy activation and blkg destruction

When switching an IO scheduler on a block device, blkcg_activate_policy()
allocates blkg_policy_data (pd) for all blkgs attached to the queue.
However, blkcg_activate_policy() may race with concurrent blkcg deletion,
leading to use-after-free and memory leak issues.

The use-after-free occurs in the following race:

T1 (blkcg_activate_policy):
  - Successfully allocates pd for blkg1 (loop0->queue, blkcgA)
  - Fails to allocate pd for blkg2 (loop0->queue, blkcgB)
  - Enters the enomem rollback path to release blkg1 resources

T2 (blkcg deletion):
  - blkcgA is deleted concurrently
  - blkg1 is freed via blkg_free_workfn()
  - blkg1->pd is freed

T1 (continued):
  - Rollback path accesses blkg1->pd->online after pd is freed
  - Triggers use-after-free

In addition, blkg_free_workfn() frees pd before removing the blkg from
q->blkg_list. This allows blkcg_activate_policy() to allocate a new pd
for a blkg that is being destroyed, leaving the newly allocated pd
unreachable when the blkg is finally freed.

Fix these races by extending blkcg_mutex coverage to serialize
blkcg_activate_policy() rollback and blkg destruction, ensuring pd
lifecycle is synchronized with blkg list visibility.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 81c1188905f88b77743d1fdeeedfc8cb7b67787d
Version < b5dae1cd0d8368b4338430ff93403df67f0b8bcc
Status affected
Version bfe46d2efe46c5c952f982e2ca94fe2ec5e58e2a
Version < 083b58373463a6e5ee60ecb135269348f68ad7df
Status affected
Version f1c006f1c6850c14040f8337753a63119bba39b9
Version < ac34e655dffa74349d885a43d098115336f53842
Status affected
Version f1c006f1c6850c14040f8337753a63119bba39b9
Version < 2cf9f50a38c1839e549a08e22aa35e8d69e2c8fd
Status affected
Version f1c006f1c6850c14040f8337753a63119bba39b9
Version < 5313d4d41739b0cb63000747c97bb1217ac45f3e
Status affected
Version 6.1.16
Version < 6.1.17
Status affected
Version 6.2.3
Version < 6.2.4
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.3
Status affected
Version 0
Version < 6.3
Status unaffected
Version <= 6.1.*
Version 6.1.17
Status unaffected
Version <= 6.2.*
Version 6.2.4
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.055
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/083b58373463a6e5ee60ecb135269348f68ad7df
https://git.kernel.org/stable/c/b5dae1cd0d8368b4338430ff93403df67f0b8bcc
https://git.kernel.org/stable/c/ac34e655dffa74349d885a43d098115336f53842
https://git.kernel.org/stable/c/2cf9f50a38c1839e549a08e22aa35e8d69e2c8fd
https://git.kernel.org/stable/c/5313d4d41739b0cb63000747c97bb1217ac45f3e