PT-2026-94530 · Linux · Linux Kernel

CVE-2026-90182

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the blk-iocost component where the delay state is not cleared when freeing policy data. The iocg kick delay() function converts large debt into a block-cgroup delay via blkcg set delay(), which sets blkg->use delay to -1 and increments blkcg->congestion count. When ioc pd free() removes the iocg from active iocgs and cancels its waitq timer, the blkcg remains marked as congested indefinitely because no further bios can arrive to reduce the debt. Consequently, blk cgroup congested() returns true for all tasks in that cgroup and its descendants, leading to reduced readahead in page cache sync ra(), skipped readahead in page cache async ra(), and throttling of anonymous folio allocation in folio throttle swaprate().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101951
CVE-2026-90182
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel