PT-2026-97995 · Linux · Linux

CVE-2026-93795

·

Publicado

2026-09-24

·

Atualizado

2026-09-24

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
blk-cgroup: fix leaks and online flag on radix tree insert failure
When radix tree insert() fails in blkg create(), the error path has two issues:
  1. blkg->online is set to true unconditionally, even when the blkg was never fully inserted. Move the assignment inside the success block.
  2. The error path calls blkg put() without first calling percpu ref kill(). Because the refcount is still in percpu mode, percpu ref put() only does this cpu sub() without checking for zero, so blkg release() is never triggered. This permanently leaks the blkg memory, its percpu iostat, policy data, the parent blkg reference, and the cgroup css reference — the latter preventing the cgroup from ever being destroyed.
Fix by replacing blkg put() with percpu ref kill(), matching the pattern used in blkg destroy().
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-93795

Produtos afetados

Linux