{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90301","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.799Z","datePublished":"2026-09-17T16:08:25.152Z","dateUpdated":"2026-09-18T17:54:25.849Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:25.849Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: o2hb: quiesce negotiate handlers and timeout work\n\nHeartbeat regions publish struct o2hb_region as the private data for the\nNEGO_TIMEOUT and NEGO_APPROVE o2net handlers as soon as make_item()\ncreates the configfs region.  The approve handler can call\no2hb_arm_timeout(), so a peer can touch the region timeout work before\ndev_store() has finished building the heartbeat runtime, or after teardown\nhas started to shut that runtime back down.\n\nThe final configfs put also has to keep reg alive until the last in-flight\no2net callback drops its handler reference. \no2net_unregister_handler_list() blocks future handler lookups, but it does\nnot wait for sc_rx_work that already passed o2net_handler_get().  That\ndrain needs to cover local listener teardown as well, where the o2net\nordered workqueue may already be inside destroy_workqueue().\n\nFix the lifetime rule in both directions.  Initialize the region delayed\nworks before publishing reg through the o2net handler table, keep new or\nstopping regions non-armable with hr_stopping, and quiesce both delayed\nworks on failed-start and teardown paths even when no heartbeat thread is\nleft to call o2hb_disarm_timeout().  Then unregister handlers before\ntearing down handler-visible region state and make the drain wait for the\nactive or destroying o2net ordered workqueue before release frees reg.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nregion lifecycle:                late negotiate callback:\n1. make_item() registers the     1. o2net_process_message() gets a\n   region handlers before           heartbeat handler for reg.\n   dev_store() has built a       2. The callback runs after the lookup\n   runnable heartbeat context.      lock is dropped and dereferences reg.\n2. A failed start or rmdir       3. An approve or timeout path tries to\n   stops the heartbeat thread,      queue reg's delayed work, or release\n   quiesces existing work, and      races the callback body after handler\n   drops the final configfs ref.    unregister.\n3. region_release() must drain   4. The callback or delayed work can\n   handler-visible o2net rx work    outlive reg unless lifecycle code\n   before freeing reg.              keeps the region non-armable and\n                                    drains the active-or-destroying\n                                    o2net workqueue.\n\nValidation reproduced this kernel report:\nKASAN slab-use-after-free in __run_timers+0x22c/0x5b0\nWrite of size 8\nCall trace:\n  dump_stack_lvl+0x66/0xa0\n  print_report+0xce/0x630\n  __run_timers+0x22c/0x5b0\n  kasan_report+0xe0/0x110\n  _raw_spin_unlock_irqrestore+0x27/0x60\n  try_to_wake_up+0x191/0xf70\n  timer_expire_remote+0xae/0xf0\n  run_timer_softirq+0x19b/0x1a0\n  handle_softirqs+0x156/0x660\n  __irq_exit_rcu+0xc4/0x160\n  irq_exit_rcu+0xe/0x20\n  sysvec_apic_timer_interrupt+0x6c/0x80\n  asm_sysvec_apic_timer_interrupt+0x1a/0x20\n\nAllocated by task stack:\n  kasan_save_stack+0x33/0x60\n  kasan_save_track+0x14/0x30\n  __kasan_kmalloc+0xaa/0xb0\n  o2hb_heartbeat_group_make_item+0x3c/0x600"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - O2HB_NEGO_APPROVE_MSG and O2HB_NEGO_TIMEOUT_MSG arrive as o2net TCP payloads. o2net_data_ready queues sc_rx_work; o2net_rx_until_empty → o2net_advance_rx → o2net_process_message looks up the handler by msg_type and hr_key and calls o2hb_nego_approve_handler or o2hb_nego_timeout_handler, so the peer supplies the triggering bytes on a routable IPv4 TCP session.\nAC:H - Memory corruption requires the region to be between o2hb_heartbeat_group_make_item() publishing handlers (hr_steady_iterations still 0, delayed work uninitialized) and INIT_DELAYED_WORK in o2hb_region_dev_store(), or o2net_handler_get() racing o2hb_region_release()'s kfree. The peer sends NEGO_APPROVE but cannot mkdir/rmdir the configfs region that opens those windows.\nPR:N - o2net_accept_one admits the TCP peer after o2nm_get_node_by_ip() and o2hb_check_node_heartbeating_from_callback(); o2net_check_handshake only compares protocol version and idle/keepalive/heartbeat timeouts. No user login or capability check runs before o2hb_nego_approve_handler, so no account on the victim is required.\nUI:N - Once an o2net session exists, the attacker triggers the bug by sending O2HB_NEGO_APPROVE_MSG. Configfs heartbeat-region create or rmdir is cluster bring-up or shutdown timing, not a victim action such as mounting a filesystem or opening a file.\nS:U - The UAF writes the freed o2hb_region from o2hb_arm_timeout() and __run_timers stay in the host kernel on that cluster node and do not cross a guest-to-host, VM, or IOMMU boundary.\nC:H - KASAN reported a slab-use-after-free of the o2hb_region allocated by o2hb_heartbeat_group_make_item. o2hb_nego_timeout_handler still reads hr_nego_node_bitmap and config_item_name after free, and reclaiming the slab gives the attacker the freed object contents, enabling disclosure of adjacent kernel memory.\nI:H - o2hb_nego_approve_handler calls o2hb_arm_timeout(), which schedule_delayed_work's hr_write_timeout_work and hr_nego_timeout_work on a not-yet-initialized or already-freed o2hb_region. The reproduced bug is an 8-byte write in __run_timers on that freed object, a UAF write that can hijack kernel control flow.\nA:H - The UAF write in __run_timers runs from run_timer_softirq and oopses the node. If the wrongly armed hr_write_timeout_work fires, o2hb_write_timeout() also calls o2quo_disk_timeout() → o2quo_fence_self(), fencing the victim."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ocfs2/cluster/heartbeat.c","fs/ocfs2/cluster/tcp.c","fs/ocfs2/cluster/tcp.h"],"versions":[{"version":"34069b886f95356d68bf8315fa648c4ab3193cdd","lessThan":"b5a2907bdeced0949bcddc84b95ba7d4cb93841b","status":"affected","versionType":"git"},{"version":"34069b886f95356d68bf8315fa648c4ab3193cdd","lessThan":"011291b70ba4832e136b7b581825b2bc0f525bf6","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ocfs2/cluster/heartbeat.c","fs/ocfs2/cluster/tcp.c","fs/ocfs2/cluster/tcp.h"],"versions":[{"version":"4.7","status":"affected"},{"version":"0","lessThan":"4.7","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.7","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.7","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b5a2907bdeced0949bcddc84b95ba7d4cb93841b"},{"url":"https://git.kernel.org/stable/c/011291b70ba4832e136b7b581825b2bc0f525bf6"}],"title":"ocfs2: o2hb: quiesce negotiate handlers and timeout work","x_generator":{"engine":"bippy-1.2.0"}}}}