PT-2026-94674 · Linux · Linux Kernel

CVE-2026-90326

·

Published

2026-09-17

·

Updated

2026-09-19

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists when switching an IO scheduler on a block device. The blkcg activate policy() function allocates blkg policy data for all blkgs attached to the queue, but it may race with concurrent blkcg deletion. This can lead to a use-after-free scenario where the rollback path in blkcg activate policy() accesses blkg1->pd->online after the data has been freed by blkg free workfn(). Additionally, because blkg free workfn() frees the policy data before removing the blkg from the q->blkg list, a new policy data object may be allocated for a blkg that is already being destroyed, resulting in a memory leak.
Recommendations Extend blkcg mutex coverage to serialize blkcg activate policy() rollback and blkg destruction to synchronize the policy data lifecycle with blkg list visibility.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102774
CVE-2026-90326

Affected Products

Linux Kernel