Impact
A race condition in the Linux kernel’s block‑cgroup subsystem allows an attacker who can trigger an I/O scheduler change on a block device at the same time as a blk‑cgroup removal to cause the kernel to free block‑cgroup data and then later access that freed memory. This use‑after‑free can result in a kernel crash or memory corruption, and the lack of proper cleanup also leads to a memory leak.
Affected Systems
All Linux kernel releases prior to the commit that introduces the blk‑cgroup activation/rollback serialization fix. Distribution kernels that have not incorporated this patch are vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8. Its EPSS score is reported as less than 1 %, indicating a low probability of exploitation in the wild, and it is not listed in CISA’s KEV catalog. Exploitation would require an ability to orchestrate the race by changing a block‑device I/O scheduler while a blk‑cgroup is being deleted, which typically requires local access and is unlikely to be remotely controllable. The remaining risk is therefore moderate, with the majority of potential impact limited to a crash or memory corruption on the affected system.
OpenCVE Enrichment