PT-2026-94649 · Linux · Linux Kernel

CVE-2026-90301

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A slab-use-after-free issue exists in the OCFS2 heartbeat (o2hb) component of the Linux kernel. The problem occurs because heartbeat regions publish the o2hb region structure as private data for NEGO TIMEOUT and NEGO APPROVE handlers via the make item() function before the heartbeat runtime is fully constructed by dev store(). This allows a peer to interact with region timeout work during the runtime build or teardown phases. Additionally, the o2net unregister handler list() function does not wait for in-flight sc rx work that has already passed o2net handler get(), potentially allowing callbacks or delayed work to outlive the o2hb region structure. This race condition can lead to memory corruption when region release() frees the region while a callback is still active.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102569
CVE-2026-90301
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel