CVE-2026-90325
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-90325, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-17
Last updated on: 2026-09-18
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
blk-cgroup: skip dying blkg in blkcg_activate_policy()
When switching IO schedulers on a block device, blkcg_activate_policy()
can race with concurrent blkcg deletion, leading to a use-after-free in
rcu_accelerate_cbs.
T1: T2:
blkg_destroy
kill(&blkg->refcnt) // blkg->refcnt=1->0
blkg_release // call_rcu(__blkg_release)
...
blkg_free_workfn
->pd_free_fn(pd)
elv_iosched_store
elevator_switch
...
iterate blkg list
blkg_get(blkg) // blkg->refcnt=0->1
list_del_init(&blkg->q_node)
blkg_put(pinned_blkg) // blkg->refcnt=1->0
blkg_release // call_rcu again
rcu_accelerate_cbs // uaf
Fix this by checking hlist_unhashed(&blkg->blkcg_node) before getting
a reference to the blkg. This is the same check used in blkg_destroy()
to detect if a blkg has already been destroyed. If the blkg is already
unhashed, skip processing it since it's being destroyed.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 81c1188905f88b77743d1fdeeedfc8cb7b67787d |
| Linux | Linux | bfe46d2efe46c5c952f982e2ca94fe2ec5e58e2a |
| Linux | Linux | f1c006f1c6850c14040f8337753a63119bba39b9 |
| Linux | Linux | f1c006f1c6850c14040f8337753a63119bba39b9 |
| Linux | Linux | f1c006f1c6850c14040f8337753a63119bba39b9 |
| Linux | Linux | f1c006f1c6850c14040f8337753a63119bba39b9 |
| Linux | Linux | f1c006f1c6850c14040f8337753a63119bba39b9 |
| Linux | Linux | 6.1.16 |
| Linux | Linux | 6.2.3 |
| Linux | Linux | 6.3 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |