PT-2026-97995 · Linux · Linux
CVE-2026-93795
·
Published
2026-09-24
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
blk-cgroup: fix leaks and online flag on radix tree insert failure
When radix tree insert() fails in blkg create(), the error path has two
issues:
-
blkg->online is set to true unconditionally, even when the blkg was never fully inserted. Move the assignment inside the success block.
-
The error path calls blkg put() without first calling percpu ref kill(). Because the refcount is still in percpu mode, percpu ref put() only does this cpu sub() without checking for zero, so blkg release() is never triggered. This permanently leaks the blkg memory, its percpu iostat, policy data, the parent blkg reference, and the cgroup css reference — the latter preventing the cgroup from ever being destroyed.
Fix by replacing blkg put() with percpu ref kill(), matching the pattern
used in blkg destroy().
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux