Description
In the Linux kernel, the following vulnerability has been resolved:

blk-cgroup: skip dying blkg in blkcg_activate_policy()

When switching IO schedulers on a block device, blkcg_activate_policy()
can race with concurrent blkcg deletion, leading to a use-after-free in
rcu_accelerate_cbs.

T1: T2:
blkg_destroy
kill(&blkg->refcnt) // blkg->refcnt=1->0
blkg_release // call_rcu(__blkg_release)
...
blkg_free_workfn
->pd_free_fn(pd)
elv_iosched_store
elevator_switch
...
iterate blkg list
blkg_get(blkg) // blkg->refcnt=0->1
list_del_init(&blkg->q_node)
blkg_put(pinned_blkg) // blkg->refcnt=1->0
blkg_release // call_rcu again
rcu_accelerate_cbs // uaf

Fix this by checking hlist_unhashed(&blkg->blkcg_node) before getting
a reference to the blkg. This is the same check used in blkg_destroy()
to detect if a blkg has already been destroyed. If the blkg is already
unhashed, skip processing it since it's being destroyed.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation to Kernel Level
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free caused by a race between switching IO schedulers on a block device and concurrent deletion of a block cgroup (blkg) in the Linux kernel. The race can free the blkg object while another thread still accesses it, leading to memory corruption in the kernel. If an attacker can trigger the scheduler switch, a local user with sufficient privileges could potentially execute code at kernel level or crash the system, compromising confidentiality, integrity, and availability of the affected host.

Affected Systems

All Linux kernel implementations that enable block cgroups are impacted. No specific kernel version numbers are listed in the CVE data; users should verify that their kernels contain the blk‑cgroup cleanup change that checks hlist_unhashed(&blkg->blkcg_node) before acquiring a reference. Both generic Linux distributions and custom kernel builds that compile the CONFIG_BLK_CGROUP subsystem are potentially affected.

Risk and Exploitability

The CVSS v3 score is 7.8, indicating high severity. The current EPSS score is less than 1 percent, so the probability of exploitation in the wild is considered very low. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is inferred to be local privileged code or root, because triggering the race requires changing IO scheduler settings. An exploit would involve manipulating the scheduler interface while a block cgroup deletion is in progress, resulting in a use‑after‑free and possible escalation of privileges to kernel RCE.

Generated by OpenCVE AI on September 20, 2026 at 00:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest Linux kernel that contains the blk‑cgroup cleanup fix – see the commit logs for the entries that add hlist_unhashed(&blkg->blkcg_node) checks. This patch eliminates the race by preventing references to a blkg that is already unhashed.
  • If a kernel update cannot be performed immediately, compile the kernel without CONFIG_BLK_CGROUP support or disable the feature at boot time using a kernel command line option; this removes the block cgroup subsystem entirely and stops the use‑after‑free scenario.
  • Regularly monitor block scheduler changes and block cgroup deletions on production systems to detect premature cleanup, and apply the patch as soon as it becomes available.

Generated by OpenCVE AI on September 20, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: skip dying blkg in blkcg_activate_policy() When switching IO schedulers on a block device, blkcg_activate_policy() can race with concurrent blkcg deletion, leading to a use-after-free in rcu_accelerate_cbs. T1: T2: blkg_destroy kill(&blkg->refcnt) // blkg->refcnt=1->0 blkg_release // call_rcu(__blkg_release) ... blkg_free_workfn ->pd_free_fn(pd) elv_iosched_store elevator_switch ... iterate blkg list blkg_get(blkg) // blkg->refcnt=0->1 list_del_init(&blkg->q_node) blkg_put(pinned_blkg) // blkg->refcnt=1->0 blkg_release // call_rcu again rcu_accelerate_cbs // uaf Fix this by checking hlist_unhashed(&blkg->blkcg_node) before getting a reference to the blkg. This is the same check used in blkg_destroy() to detect if a blkg has already been destroyed. If the blkg is already unhashed, skip processing it since it's being destroyed.
Title blk-cgroup: skip dying blkg in blkcg_activate_policy()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:37.929Z

Reserved: 2026-09-11T19:38:34.802Z

Link: CVE-2026-90325

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:30.540

Modified: 2026-09-18T18:17:53.960

Link: CVE-2026-90325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:30:16Z

Weaknesses