PT-2026-94650 · Linux · Linux Kernel

CVE-2026-90302

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists in the OCFS2 heartbeat and o2net teardown process. When a local-node teardown occurs via o2net stop listening(), heartbeat callbacks may remain registered. If a node-down event triggers o2net disconnect node() and o2net set nn state() while the teardown process is destroying the o2net wq workqueue, the system may attempt to queue or flush operations on a dead workqueue. This leads to a slab-use-after-free (a situation where the system accesses memory after it has been freed) in the queue work() function. The issue involves the following function call chain: o2hb run event list() -> o2net hb node down cb() -> o2net disconnect node() -> o2net set nn state() -> queue delayed work on() -> queue work().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102873
CVE-2026-90302
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel