PT-2026-94674 · Linux · Linux Kernel
CVE-2026-90326
·
Published
2026-09-17
·
Updated
2026-09-19
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A race condition exists when switching an IO scheduler on a block device. The
blkcg activate policy() function allocates blkg policy data for all blkgs attached to the queue, but it may race with concurrent blkcg deletion. This can lead to a use-after-free scenario where the rollback path in blkcg activate policy() accesses blkg1->pd->online after the data has been freed by blkg free workfn(). Additionally, because blkg free workfn() frees the policy data before removing the blkg from the q->blkg list, a new policy data object may be allocated for a blkg that is already being destroyed, resulting in a memory leak.Recommendations
Extend
blkcg mutex coverage to serialize blkcg activate policy() rollback and blkg destruction to synchronize the policy data lifecycle with blkg list visibility.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel