CVE-2026-90326 (GCVE-0-2026-90326)

Vulnerability from cvelistv5 – Published: 2026-09-17 16:08 – Updated: 2026-09-18 17:54
VLAI
Title
blk-cgroup: fix race between policy activation and blkg destruction
Summary
In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix race between policy activation and blkg destruction When switching an IO scheduler on a block device, blkcg_activate_policy() allocates blkg_policy_data (pd) for all blkgs attached to the queue. However, blkcg_activate_policy() may race with concurrent blkcg deletion, leading to use-after-free and memory leak issues. The use-after-free occurs in the following race: T1 (blkcg_activate_policy): - Successfully allocates pd for blkg1 (loop0->queue, blkcgA) - Fails to allocate pd for blkg2 (loop0->queue, blkcgB) - Enters the enomem rollback path to release blkg1 resources T2 (blkcg deletion): - blkcgA is deleted concurrently - blkg1 is freed via blkg_free_workfn() - blkg1->pd is freed T1 (continued): - Rollback path accesses blkg1->pd->online after pd is freed - Triggers use-after-free In addition, blkg_free_workfn() frees pd before removing the blkg from q->blkg_list. This allows blkcg_activate_policy() to allocate a new pd for a blkg that is being destroyed, leaving the newly allocated pd unreachable when the blkg is finally freed. Fix these races by extending blkcg_mutex coverage to serialize blkcg_activate_policy() rollback and blkg destruction, ensuring pd lifecycle is synchronized with blkg list visibility.
Impacted products
Vendor Product Version
Linux Linux Affected: 81c1188905f88b77743d1fdeeedfc8cb7b67787d , < b5dae1cd0d8368b4338430ff93403df67f0b8bcc (git)
Affected: bfe46d2efe46c5c952f982e2ca94fe2ec5e58e2a , < 083b58373463a6e5ee60ecb135269348f68ad7df (git)
Affected: f1c006f1c6850c14040f8337753a63119bba39b9 , < ac34e655dffa74349d885a43d098115336f53842 (git)
Affected: f1c006f1c6850c14040f8337753a63119bba39b9 , < 2cf9f50a38c1839e549a08e22aa35e8d69e2c8fd (git)
Affected: f1c006f1c6850c14040f8337753a63119bba39b9 , < 5313d4d41739b0cb63000747c97bb1217ac45f3e (git)
Affected: 6.1.16 , < 6.1.17 (semver)
Affected: 6.2.3 , < 6.2.4 (semver)
Create a notification for this product.
Linux Linux Affected: 6.3
Unaffected: 0 , < 6.3 (semver)
Unaffected: 6.1.17 , ≤ 6.1.* (semver)
Unaffected: 6.2.4 , ≤ 6.2.* (semver)
Unaffected: 6.18.52 , ≤ 6.18.* (semver)
Unaffected: 7.2.6 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc1 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "block/blk-cgroup.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "b5dae1cd0d8368b4338430ff93403df67f0b8bcc",
              "status": "affected",
              "version": "81c1188905f88b77743d1fdeeedfc8cb7b67787d",
              "versionType": "git"
            },
            {
              "lessThan": "083b58373463a6e5ee60ecb135269348f68ad7df",
              "status": "affected",
              "version": "bfe46d2efe46c5c952f982e2ca94fe2ec5e58e2a",
              "versionType": "git"
            },
            {
              "lessThan": "ac34e655dffa74349d885a43d098115336f53842",
              "status": "affected",
              "version": "f1c006f1c6850c14040f8337753a63119bba39b9",
              "versionType": "git"
            },
            {
              "lessThan": "2cf9f50a38c1839e549a08e22aa35e8d69e2c8fd",
              "status": "affected",
              "version": "f1c006f1c6850c14040f8337753a63119bba39b9",
              "versionType": "git"
            },
            {
              "lessThan": "5313d4d41739b0cb63000747c97bb1217ac45f3e",
              "status": "affected",
              "version": "f1c006f1c6850c14040f8337753a63119bba39b9",
              "versionType": "git"
            },
            {
              "lessThan": "6.1.17",
              "status": "affected",
              "version": "6.1.16",
              "versionType": "semver"
            },
            {
              "lessThan": "6.2.4",
              "status": "affected",
              "version": "6.2.3",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "block/blk-cgroup.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.3"
            },
            {
              "lessThan": "6.3",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.17",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.2.*",
              "status": "unaffected",
              "version": "6.2.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.17",
                  "versionStartIncluding": "6.1.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.2.4",
                  "versionStartIncluding": "6.2.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.52",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.6",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc1",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: fix race between policy activation and blkg destruction\n\nWhen switching an IO scheduler on a block device, blkcg_activate_policy()\nallocates blkg_policy_data (pd) for all blkgs attached to the queue.\nHowever, blkcg_activate_policy() may race with concurrent blkcg deletion,\nleading to use-after-free and memory leak issues.\n\nThe use-after-free occurs in the following race:\n\nT1 (blkcg_activate_policy):\n  - Successfully allocates pd for blkg1 (loop0-\u003equeue, blkcgA)\n  - Fails to allocate pd for blkg2 (loop0-\u003equeue, blkcgB)\n  - Enters the enomem rollback path to release blkg1 resources\n\nT2 (blkcg deletion):\n  - blkcgA is deleted concurrently\n  - blkg1 is freed via blkg_free_workfn()\n  - blkg1-\u003epd is freed\n\nT1 (continued):\n  - Rollback path accesses blkg1-\u003epd-\u003eonline after pd is freed\n  - Triggers use-after-free\n\nIn addition, blkg_free_workfn() frees pd before removing the blkg from\nq-\u003eblkg_list. This allows blkcg_activate_policy() to allocate a new pd\nfor a blkg that is being destroyed, leaving the newly allocated pd\nunreachable when the blkg is finally freed.\n\nFix these races by extending blkcg_mutex coverage to serialize\nblkcg_activate_policy() rollback and blkg destruction, ensuring pd\nlifecycle is synchronized with blkg list visibility."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The triggering operations are local cgroupfs writes: tg_set_limit() (io.max) or iolatency_set_limit() (io.latency) call blk_throtl_init()/blk_iolatency_init() then blkcg_activate_policy(), while cgroup_rmdir() runs blkcg_css_offline() into blkg_free_workfn(); elv_iosched_store() is an alternate local sysfs path. No remote protocol carries the race inputs.\nAC:L - The attacker drives both sides: one thread writes io.max/io.latency so blkcg_activate_policy() attaches pd without q-\u003eblkcg_mutex, while another rmdirs sibling blkcgs so blkg_free_workfn() calls pd_free_fn() on the same blkg-\u003epd[] before list_del. That interleaving does not depend on GFP_KERNEL failure; the documented enomem rollback UAF on pd-\u003eonline is an extra window the attacker can retry.\nPR:L - tg_set_limit() and iolatency_set_limit() have no capable() check; io.max/io.latency are CFTYPE_NOT_ON_ROOT S_IWUSR files, and blkg_conf_open_bdev() uses blkdev_get_no_open() with no device permission check. A delegated cgroup-v2 subtree owner (typical systemd user slice or rootless container) can write those files and rmdir child cgroups; scheduler sysfs is a stricter alternate path.\nUI:N - The attacker writes io.max/io.latency in cgroups they own and rmdirs those cgroups themselves; no other user must mount a device, open a file, or otherwise participate.\nS:U - The UAF corrupts kernel blkg_policy_data (throtl_grp/iolatency_grp) in the host io controller; impact stays in the kernel\u0027s authority and does not cross a VM, IOMMU, or other security boundary.\nC:H - blkg_free_workfn() frees blkg-\u003epd[] while the object remains on q-\u003eblkg_list, so blkcg_activate_policy()\u0027s enomem path reads pd-\u003eonline and pd_offline_fn() (throtl_pd_offline()/tg_flush_bios()) walks the freed throtl_grp; spraying the slab reclaims that object for an arbitrary kernel read.\nI:H - The same freed pd is written (pd-\u003eonline = false) and passed to pol-\u003epd_free_fn() again (throtl_pd_free() does timer_delete_sync() and call_rcu()), a double-free of throtl_grp/iolatency_grp that yields a kernel write/control-flow primitive.\nA:H - Use-after-free and double-free of blkg_policy_data in blkcg_activate_policy() versus blkg_free_workfn() oops/panic the kernel even when not turned into a full memory primitive."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-18T17:54:39.274Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b5dae1cd0d8368b4338430ff93403df67f0b8bcc"
        },
        {
          "url": "https://git.kernel.org/stable/c/083b58373463a6e5ee60ecb135269348f68ad7df"
        },
        {
          "url": "https://git.kernel.org/stable/c/ac34e655dffa74349d885a43d098115336f53842"
        },
        {
          "url": "https://git.kernel.org/stable/c/2cf9f50a38c1839e549a08e22aa35e8d69e2c8fd"
        },
        {
          "url": "https://git.kernel.org/stable/c/5313d4d41739b0cb63000747c97bb1217ac45f3e"
        }
      ],
      "title": "blk-cgroup: fix race between policy activation and blkg destruction",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-90326",
    "datePublished": "2026-09-17T16:08:41.374Z",
    "dateReserved": "2026-09-11T19:38:34.802Z",
    "dateUpdated": "2026-09-18T17:54:39.274Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-90326",
      "date": "2026-10-04",
      "epss": "0.0017",
      "percentile": "0.05718"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "block/blk-cgroup.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "b5dae1cd0d8368b4338430ff93403df67f0b8bcc",
                    "status": "affected",
                    "version": "81c1188905f88b77743d1fdeeedfc8cb7b67787d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "083b58373463a6e5ee60ecb135269348f68ad7df",
                    "status": "affected",
                    "version": "bfe46d2efe46c5c952f982e2ca94fe2ec5e58e2a",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "ac34e655dffa74349d885a43d098115336f53842",
                    "status": "affected",
                    "version": "f1c006f1c6850c14040f8337753a63119bba39b9",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "2cf9f50a38c1839e549a08e22aa35e8d69e2c8fd",
                    "status": "affected",
                    "version": "f1c006f1c6850c14040f8337753a63119bba39b9",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5313d4d41739b0cb63000747c97bb1217ac45f3e",
                    "status": "affected",
                    "version": "f1c006f1c6850c14040f8337753a63119bba39b9",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "6.1.17",
                    "status": "affected",
                    "version": "6.1.16",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "6.2.4",
                    "status": "affected",
                    "version": "6.2.3",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "block/blk-cgroup.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "lessThan": "6.3",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.1.*",
                    "status": "unaffected",
                    "version": "6.1.17",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.2.*",
                    "status": "unaffected",
                    "version": "6.2.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.52",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.6",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc1",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: fix race between policy activation and blkg destruction\n\nWhen switching an IO scheduler on a block device, blkcg_activate_policy()\nallocates blkg_policy_data (pd) for all blkgs attached to the queue.\nHowever, blkcg_activate_policy() may race with concurrent blkcg deletion,\nleading to use-after-free and memory leak issues.\n\nThe use-after-free occurs in the following race:\n\nT1 (blkcg_activate_policy):\n  - Successfully allocates pd for blkg1 (loop0-\u003equeue, blkcgA)\n  - Fails to allocate pd for blkg2 (loop0-\u003equeue, blkcgB)\n  - Enters the enomem rollback path to release blkg1 resources\n\nT2 (blkcg deletion):\n  - blkcgA is deleted concurrently\n  - blkg1 is freed via blkg_free_workfn()\n  - blkg1-\u003epd is freed\n\nT1 (continued):\n  - Rollback path accesses blkg1-\u003epd-\u003eonline after pd is freed\n  - Triggers use-after-free\n\nIn addition, blkg_free_workfn() frees pd before removing the blkg from\nq-\u003eblkg_list. This allows blkcg_activate_policy() to allocate a new pd\nfor a blkg that is being destroyed, leaving the newly allocated pd\nunreachable when the blkg is finally freed.\n\nFix these races by extending blkcg_mutex coverage to serialize\nblkcg_activate_policy() rollback and blkg destruction, ensuring pd\nlifecycle is synchronized with blkg list visibility."
          }
        ],
        "id": "CVE-2026-90326",
        "lastModified": "2026-09-18T18:17:54.130",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 1.8,
              "impactScore": 5.9,
              "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
              "type": "Secondary"
            }
          ]
        },
        "published": "2026-09-17T17:17:30.673",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/083b58373463a6e5ee60ecb135269348f68ad7df"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/2cf9f50a38c1839e549a08e22aa35e8d69e2c8fd"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/5313d4d41739b0cb63000747c97bb1217ac45f3e"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/ac34e655dffa74349d885a43d098115336f53842"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/b5dae1cd0d8368b4338430ff93403df67f0b8bcc"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…