PT-2026-94649 · Linux · Linux Kernel
CVE-2026-90301
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A slab-use-after-free issue exists in the OCFS2 heartbeat (o2hb) component of the Linux kernel. The problem occurs because heartbeat regions publish the
o2hb region structure as private data for NEGO TIMEOUT and NEGO APPROVE handlers via the make item() function before the heartbeat runtime is fully constructed by dev store(). This allows a peer to interact with region timeout work during the runtime build or teardown phases. Additionally, the o2net unregister handler list() function does not wait for in-flight sc rx work that has already passed o2net handler get(), potentially allowing callbacks or delayed work to outlive the o2hb region structure. This race condition can lead to memory corruption when region release() frees the region while a callback is still active.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel