{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90325","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.802Z","datePublished":"2026-09-17T16:08:40.710Z","dateUpdated":"2026-09-18T17:54:37.929Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:37.929Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: skip dying blkg in blkcg_activate_policy()\n\nWhen switching IO schedulers on a block device, blkcg_activate_policy()\ncan race with concurrent blkcg deletion, leading to a use-after-free in\nrcu_accelerate_cbs.\n\nT1:                               T2:\n                                  blkg_destroy\n                                  kill(&blkg->refcnt) // blkg->refcnt=1->0\n                                  blkg_release // call_rcu(__blkg_release)\n                                  ...\n                                  blkg_free_workfn\n                                  ->pd_free_fn(pd)\nelv_iosched_store\nelevator_switch\n...\niterate blkg list\nblkg_get(blkg) // blkg->refcnt=0->1\n                                  list_del_init(&blkg->q_node)\nblkg_put(pinned_blkg) // blkg->refcnt=1->0\nblkg_release // call_rcu again\nrcu_accelerate_cbs // uaf\n\nFix this by checking hlist_unhashed(&blkg->blkcg_node) before getting\na reference to the blkg. This is the same check used in blkg_destroy()\nto detect if a blkg has already been destroyed. If the blkg is already\nunhashed, skip processing it since it's being destroyed."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached by writing the local sysfs file /sys/block/<dev>/queue/scheduler (elv_iosched_store → elevator_switch → bfq_create_group_hierarchy → blkcg_activate_policy) or by writing the local cgroup files io.max (tg_set_limit → blk_throtl_init) or io.latency (iolatency_set_limit → blk_iolatency_init). No remote protocol carries the triggering state.\nAC:L - The attacker drives both sides: one thread writes io.max/io.latency or queue/scheduler so blkcg_activate_policy() takes the GFP_NOWAIT-fail retry and calls blkg_get() on a q->blkg_list entry, while another rmdirs a sibling io cgroup so blkcg_css_offline() → blkg_destroy() kills that blkg's percpu_ref. The mkdir/write/rmdir cycle can be repeated until the window hits.\nPR:L - cgroup_add_file() creates io.max and io.latency with mode 0644 and current_fsuid(), so an unprivileged user who mkdir's in a delegated cgroup v2 subtree (systemd user@.service, rootless containers) can write those files and rmdir the cgroup. tg_set_limit()/iolatency_set_limit() have no capability check, and blkg_conf_open_bdev() looks up the disk by MAJ:MIN via blkdev_get_no_open() without opening it.\nUI:N - The attacker performs the mkdir, the io.max/io.latency or scheduler write that enters blkcg_activate_policy(), and the concurrent rmdir that runs blkg_destroy(), all from its own processes; no other user must mount a device or open a file.\nS:U - Double call_rcu on blkg->rcu_head corrupts host-kernel RCU callback lists and the slab-backed blkcg_gq. That stays inside the same kernel security authority and is not a VM, IOMMU, or hypervisor escape.\nC:H - blkcg_activate_policy() calls blkg_get() (percpu_ref_get, not tryget) on a blkg whose refcnt blkg_destroy() already killed, resurrecting it; the matching blkg_put() after mutex_unlock races blkg_free_workfn()'s kfree(blkg) and issues a second call_rcu on the same rcu_head, which the report shows as a UAF in rcu_accelerate_cbs. A UAF on the RCU list and blkcg_gq is an arbitrary kernel-memory read.\nI:H - The second call_rcu(&blkg->rcu_head) from the resurrected blkg_put() corrupts the RCU callback list (rcu_accelerate_cbs) while blkg_free_workfn() still does list_del_init() and pd_free_fn() on that object. Those writes through a freed, sprayable blkcg_gq are a kernel write primitive suitable for control-flow hijack.\nA:H - The commit documents a use-after-free in rcu_accelerate_cbs from the second call_rcu on blkg->rcu_head after blkg_get() resurrects a killed ref; that UAF oopses or panics the kernel even if it is not further exploited."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["block/blk-cgroup.c"],"versions":[{"version":"81c1188905f88b77743d1fdeeedfc8cb7b67787d","lessThan":"b5dae1cd0d8368b4338430ff93403df67f0b8bcc","status":"affected","versionType":"git"},{"version":"bfe46d2efe46c5c952f982e2ca94fe2ec5e58e2a","lessThan":"083b58373463a6e5ee60ecb135269348f68ad7df","status":"affected","versionType":"git"},{"version":"f1c006f1c6850c14040f8337753a63119bba39b9","lessThan":"1a267295b1ea6a6477963f3fda84adfecd48fcad","status":"affected","versionType":"git"},{"version":"f1c006f1c6850c14040f8337753a63119bba39b9","lessThan":"7337d012ca3fc3a6a2d1c8e2a19c6d97c38b410d","status":"affected","versionType":"git"},{"version":"f1c006f1c6850c14040f8337753a63119bba39b9","lessThan":"3d8c3da95c75a4d312e272fc7b4076dd3ba9115c","status":"affected","versionType":"git"},{"version":"f1c006f1c6850c14040f8337753a63119bba39b9","lessThan":"d8c872901e6459339374e9eea80aa919176c2ccd","status":"affected","versionType":"git"},{"version":"f1c006f1c6850c14040f8337753a63119bba39b9","lessThan":"5e9220389920f33b6a804d50c548cd0cd1b04634","status":"affected","versionType":"git"},{"version":"6.1.16","lessThan":"6.1.17","status":"affected","versionType":"semver"},{"version":"6.2.3","lessThan":"6.2.4","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["block/blk-cgroup.c"],"versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","status":"unaffected","versionType":"semver"},{"version":"6.1.17","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.2.4","lessThanOrEqual":"6.2.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.16","versionEndExcluding":"6.1.17"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2.3","versionEndExcluding":"6.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b5dae1cd0d8368b4338430ff93403df67f0b8bcc"},{"url":"https://git.kernel.org/stable/c/083b58373463a6e5ee60ecb135269348f68ad7df"},{"url":"https://git.kernel.org/stable/c/1a267295b1ea6a6477963f3fda84adfecd48fcad"},{"url":"https://git.kernel.org/stable/c/7337d012ca3fc3a6a2d1c8e2a19c6d97c38b410d"},{"url":"https://git.kernel.org/stable/c/3d8c3da95c75a4d312e272fc7b4076dd3ba9115c"},{"url":"https://git.kernel.org/stable/c/d8c872901e6459339374e9eea80aa919176c2ccd"},{"url":"https://git.kernel.org/stable/c/5e9220389920f33b6a804d50c548cd0cd1b04634"}],"title":"blk-cgroup: skip dying blkg in blkcg_activate_policy()","x_generator":{"engine":"bippy-1.2.0"}}}}