CVE-2026-90326
CVE CVE-2026-90326EUVD EUVD-2026-81987Veröffentlicht 2026-09-17T16:08:41.000ZZuletzt geändert 2026-09-18T17:54:39.000ZCVSS 7.8
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix race between policy activation and blkg destruction When switching an IO scheduler on a block device, blkcg_activate_policy() allocates blkg_policy_data (pd) for all blkgs attached to the queue. However, blkcg_activate_policy() may race with concurrent blkcg deletion, leading to use-after-free and memory leak issues. The use-after-free occurs in the following race: T1 (blkcg_activate_policy): - Successfully allocates pd for blkg1 (loop0->queue, blkcgA) - Fails to allocate pd for blkg2 (loop0->queue, blkcgB) - Enters the enomem rollback path to release blkg1 resources T2 (blkcg deletion): - blkcgA is deleted concurrently - blkg1 is freed via blkg_free_workfn() - blkg1->pd is freed T1 (continued): - Rollback path accesses blkg1->pd->online after pd is freed - Triggers use-after-free In addition, blkg_free_workfn() frees pd before removing the blkg from q->blkg_list. This allows blkcg_activate_policy() to allocate a new pd for a blkg that is being destroyed, leaving the newly allocated pd unreachable when the blkg is finally freed. Fix these races by extending blkcg_mutex coverage to serialize blkcg_activate_policy() rollback and blkg destruction, ensuring pd lifecycle is synchronized with blkg list visibility.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux patch: 7.3-rc1; f1c006f1c6850c14040f8337753a63119bba39b9 <2cf9f50a38c1839e549a08e22aa35e8d69e2c8fd; bfe46d2efe46c5c952f982e2ca94fe2ec5e58e2a <083b58373463a6e5ee60ecb135269348f68ad7df; 81c1188905f88b77743d1fdeeedfc8cb7b67787d <b5dae1cd0d8368b4338430ff93403df67f0b8bcc; patch: 0; 6.2.3 <6.2.4; f1c006f1c6850c14040f8337753a63119bba39b9 <5313d4d41739b0cb63000747c97bb1217ac45f3e; patch: 6.18.52; patch: 7.2.6; patch: 6.1.17; 6.3; f1c006f1c6850c14040f8337753a63119bba39b9 <ac34e655dffa74349d885a43d098115336f53842; patch: 6.2.4; 6.1.16 <6.1.17
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.