Impact
The vulnerability is a use‑after‑free caused by a race between switching IO schedulers on a block device and concurrent deletion of a block cgroup (blkg) in the Linux kernel. The race can free the blkg object while another thread still accesses it, leading to memory corruption in the kernel. If an attacker can trigger the scheduler switch, a local user with sufficient privileges could potentially execute code at kernel level or crash the system, compromising confidentiality, integrity, and availability of the affected host.
Affected Systems
All Linux kernel implementations that enable block cgroups are impacted. No specific kernel version numbers are listed in the CVE data; users should verify that their kernels contain the blk‑cgroup cleanup change that checks hlist_unhashed(&blkg->blkcg_node) before acquiring a reference. Both generic Linux distributions and custom kernel builds that compile the CONFIG_BLK_CGROUP subsystem are potentially affected.
Risk and Exploitability
The CVSS v3 score is 7.8, indicating high severity. The current EPSS score is less than 1 percent, so the probability of exploitation in the wild is considered very low. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is inferred to be local privileged code or root, because triggering the race requires changing IO scheduler settings. An exploit would involve manipulating the scheduler interface while a block cgroup deletion is in progress, resulting in a use‑after‑free and possible escalation of privileges to kernel RCE.
OpenCVE Enrichment
Debian DLA
Debian DSA