Description
In the Linux kernel, the following vulnerability has been resolved:

blk-cgroup: fix race between policy activation and blkg destruction

When switching an IO scheduler on a block device, blkcg_activate_policy()
allocates blkg_policy_data (pd) for all blkgs attached to the queue.
However, blkcg_activate_policy() may race with concurrent blkcg deletion,
leading to use-after-free and memory leak issues.

The use-after-free occurs in the following race:

T1 (blkcg_activate_policy):
- Successfully allocates pd for blkg1 (loop0->queue, blkcgA)
- Fails to allocate pd for blkg2 (loop0->queue, blkcgB)
- Enters the enomem rollback path to release blkg1 resources

T2 (blkcg deletion):
- blkcgA is deleted concurrently
- blkg1 is freed via blkg_free_workfn()
- blkg1->pd is freed

T1 (continued):
- Rollback path accesses blkg1->pd->online after pd is freed
- Triggers use-after-free

In addition, blkg_free_workfn() frees pd before removing the blkg from
q->blkg_list. This allows blkcg_activate_policy() to allocate a new pd
for a blkg that is being destroyed, leaving the newly allocated pd
unreachable when the blkg is finally freed.

Fix these races by extending blkcg_mutex coverage to serialize
blkcg_activate_policy() rollback and blkg destruction, ensuring pd
lifecycle is synchronized with blkg list visibility.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free
Action: Patch
AI Analysis

Impact

A race condition in the Linux kernel’s block‑cgroup subsystem allows an attacker who can trigger an I/O scheduler change on a block device at the same time as a blk‑cgroup removal to cause the kernel to free block‑cgroup data and then later access that freed memory. This use‑after‑free can result in a kernel crash or memory corruption, and the lack of proper cleanup also leads to a memory leak.

Affected Systems

All Linux kernel releases prior to the commit that introduces the blk‑cgroup activation/rollback serialization fix. Distribution kernels that have not incorporated this patch are vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 7.8. Its EPSS score is reported as less than 1 %, indicating a low probability of exploitation in the wild, and it is not listed in CISA’s KEV catalog. Exploitation would require an ability to orchestrate the race by changing a block‑device I/O scheduler while a blk‑cgroup is being deleted, which typically requires local access and is unlikely to be remotely controllable. The remaining risk is therefore moderate, with the majority of potential impact limited to a crash or memory corruption on the affected system.

Generated by OpenCVE AI on September 20, 2026 at 03:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that contains the blk‑cgroup race fix
  • Reboot the system so the patched kernel is active
  • If the patch cannot be applied immediately, disable blk‑cgroup support by compiling the kernel with CONFIG_BLOCK_CGROUP disabled or removing the vendor’s configuration that enables it

Generated by OpenCVE AI on September 20, 2026 at 03:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-789

Sun, 20 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix race between policy activation and blkg destruction When switching an IO scheduler on a block device, blkcg_activate_policy() allocates blkg_policy_data (pd) for all blkgs attached to the queue. However, blkcg_activate_policy() may race with concurrent blkcg deletion, leading to use-after-free and memory leak issues. The use-after-free occurs in the following race: T1 (blkcg_activate_policy): - Successfully allocates pd for blkg1 (loop0->queue, blkcgA) - Fails to allocate pd for blkg2 (loop0->queue, blkcgB) - Enters the enomem rollback path to release blkg1 resources T2 (blkcg deletion): - blkcgA is deleted concurrently - blkg1 is freed via blkg_free_workfn() - blkg1->pd is freed T1 (continued): - Rollback path accesses blkg1->pd->online after pd is freed - Triggers use-after-free In addition, blkg_free_workfn() frees pd before removing the blkg from q->blkg_list. This allows blkcg_activate_policy() to allocate a new pd for a blkg that is being destroyed, leaving the newly allocated pd unreachable when the blkg is finally freed. Fix these races by extending blkcg_mutex coverage to serialize blkcg_activate_policy() rollback and blkg destruction, ensuring pd lifecycle is synchronized with blkg list visibility.
Title blk-cgroup: fix race between policy activation and blkg destruction
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:39.274Z

Reserved: 2026-09-11T19:38:34.802Z

Link: CVE-2026-90326

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:30.673

Modified: 2026-09-18T18:17:54.130

Link: CVE-2026-90326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:30:13Z

Weaknesses
  • CWE-416

    Use After Free

  • CWE-789

    Memory Allocation with Excessive Size Value