{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64378","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T15:36:31.784Z","datePublished":"2026-07-25T08:50:29.006Z","dateUpdated":"2026-08-17T04:54:29.511Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T04:54:29.511Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwriteback: fix race between cgroup_writeback_umount() and inode_switch_wbs()\n\nWhen a container exits, the following BUG_ON() is occasionally triggered:\n\n==================================================================\n VFS: Busy inodes after unmount of sdb (ext4)\n ------------[ cut here ]------------\n kernel BUG at fs/super.c:695!\n CPU: 3 PID: 6 Comm: containerd-shim Tainted: G OE K 6.6 #1\n pstate: 63400009 (nZCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n pc : generic_shutdown_super+0xf0/0x100\n lr : generic_shutdown_super+0xf0/0x100\n Call trace:\n  generic_shutdown_super+0xf0/0x100\n  kill_block_super+0x20/0x48\n  ext4_kill_sb+0x28/0x60\n  deactivate_locked_super+0x54/0x130\n  deactivate_super+0x84/0xa0\n  cleanup_mnt+0xa4/0x140\n  __cleanup_mnt+0x18/0x28\n  task_work_run+0x78/0xe0\n  do_notify_resume+0x204/0x240\n==================================================================\n\nThe root cause is a race between cgroup_writeback_umount() and\ninode_switch_wbs()/cleanup_offline_cgwb(). There is a window between\ninode_prepare_wbs_switch() returning true and the subsequent\nwb_queue_isw() call. Following is the process that triggers the issue:\n\n      CPU A (umount)           |          CPU B (writeback)\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n                                 inode_switch_wbs/cleanup_offline_cgwb\n                                  atomic_inc(&isw_nr_in_flight)\n                                  inode_prepare_wbs_switch\n                                   -> passes SB_ACTIVE check\n                                   __iget(inode)\n generic_shutdown_super\n  sb->s_flags &= ~SB_ACTIVE\n  cgroup_writeback_umount(sb)\n   smp_mb()\n   atomic_read(&isw_nr_in_flight)\n   rcu_barrier()\n    -> no pending RCU callbacks\n   flush_workqueue(isw_wq)\n    -> nothing queued, returns\n  evict_inodes(sb)\n   -> Inode skipped as isw still holds a ref.\n  sop->put_super(sb)\n   /* destroys percpu counters */\n  -> VFS: Busy inodes after unmount!\n                                  wb_queue_isw()\n                                   queue_work(isw_wq, ...)\n                                  /* later in work function */\n                                  inode_switch_wbs_work_fn\n                                   process_inode_switch_wbs\n                                    iput() -> evict\n                                     percpu_counter_dec() // UAF!\n\nFix this by extending the RCU read-side critical section in\ninode_switch_wbs() and cleanup_offline_cgwb() to cover from\ninode_prepare_wbs_switch() through wb_queue_isw().  Since there is\nno sleep in this window, rcu_read_lock() can be used.  Then add a\nsynchronize_rcu() in cgroup_writeback_umount() before the existing\nrcu_barrier(), so that all in-flight switchers that have passed the\nSB_ACTIVE check have completed queue_work() before flush_workqueue()\nis called.\n\nThe existing rcu_barrier() is intentionally retained so this fix can\nbe backported unchanged to stable kernels (5.10.y, 6.6.y, ...) that\nstill queue switches via queue_rcu_work(). It is a no-op on current\nmainline (since commit e1b849cfa6b6 (\"writeback: Avoid contention on\nwb->list_lock when switching inodes\")) and is removed in a follow-up\npatch."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerability is reached through local filesystem writes, cgroup teardown, and mount-namespace or filesystem unmount paths; no network protocol directly reaches the race.\nAC:L - An attacker can churn cgroup writeback switches while repeatedly triggering container or mount teardown, controlling both racing activities and amplifying the timing window.\nPR:L - A basic local or container user can dirty writable files and initiate its own cgroup or namespace teardown; lifecycle infrastructure can perform the privileged final unmount automatically.\nUI:N - The attacker can generate the writeback state and trigger teardown without requiring another user to perform an action.\nS:U - The resulting corruption affects the same host kernel security authority and does not inherently cross a VM or hardware isolation boundary.\nC:H - The delayed worker can access superblock-private state after it and its per-CPU counters have been freed, creating an exploitable use-after-free capable of exposing arbitrary kernel memory.\nI:H - The freed superblock and per-CPU counter pointers are subsequently dereferenced and modified, potentially providing attacker-influenced kernel writes and control-flow hijacking.\nA:H - The race demonstrably triggers the busy-inode BUG_ON, and configurations continuing past that check encounter a use-after-free capable of causing an oops or kernel panic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/fs-writeback.c"],"versions":[{"version":"a1a0e23e49037c23ea84bc8cc146a03584d13577","lessThan":"087d5b8b501c570f84bf655164e6698c3ce146e0","status":"affected","versionType":"git"},{"version":"a1a0e23e49037c23ea84bc8cc146a03584d13577","lessThan":"3c9c9648f77e4d14e50676bc51c2174ba9c8d361","status":"affected","versionType":"git"},{"version":"a1a0e23e49037c23ea84bc8cc146a03584d13577","lessThan":"5c3265f3252b2ee50707adaaa3f9bd0df3df72de","status":"affected","versionType":"git"},{"version":"a1a0e23e49037c23ea84bc8cc146a03584d13577","lessThan":"c923cc3cb5cd8945ceaf08252754110643446593","status":"affected","versionType":"git"},{"version":"a1a0e23e49037c23ea84bc8cc146a03584d13577","lessThan":"685fc15a410885b6d4dee64de0dce721b9428b12","status":"affected","versionType":"git"},{"version":"a1a0e23e49037c23ea84bc8cc146a03584d13577","lessThan":"53eeaf4d63068dbc7708b0c7adb20151c812feca","status":"affected","versionType":"git"},{"version":"a1a0e23e49037c23ea84bc8cc146a03584d13577","lessThan":"cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d","status":"affected","versionType":"git"},{"version":"c5cbbec54fe71c4de2d34f8c0ec8fbfdd7f17339","status":"affected","versionType":"git"},{"version":"4.4.5","lessThan":"4.5","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/fs-writeback.c"],"versions":[{"version":"4.5","status":"affected"},{"version":"0","lessThan":"4.5","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5","versionEndExcluding":"6.12.96"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5","versionEndExcluding":"6.18.39"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5","versionEndExcluding":"7.1.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.4.5"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/087d5b8b501c570f84bf655164e6698c3ce146e0"},{"url":"https://git.kernel.org/stable/c/3c9c9648f77e4d14e50676bc51c2174ba9c8d361"},{"url":"https://git.kernel.org/stable/c/5c3265f3252b2ee50707adaaa3f9bd0df3df72de"},{"url":"https://git.kernel.org/stable/c/c923cc3cb5cd8945ceaf08252754110643446593"},{"url":"https://git.kernel.org/stable/c/685fc15a410885b6d4dee64de0dce721b9428b12"},{"url":"https://git.kernel.org/stable/c/53eeaf4d63068dbc7708b0c7adb20151c812feca"},{"url":"https://git.kernel.org/stable/c/cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d"}],"title":"writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()","x_generator":{"engine":"bippy-1.2.0"}}}}