Junglewise Threat Intelligence

CVE-2026-31586: Linux Kernel use-after-free in cgwb_release_workfn

CVE-2026-31586 · Severity: high · CVSS 7.8 · Published 2026-04-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's memory management and block control group (blk-cgroup) components could allow a local user to cause a system crash or potentially execute unauthorized actions. The issue occurs during the cleanup process of background writeback operations, where the system incorrectly accesses memory that has already been freed. This can lead to system instability, data corruption, or a complete service outage on affected servers.

Technical details

A use-after-free (UAF) vulnerability exists in mm/backing-dev.c within the cgwb_release_workfn() function. The root cause is a race condition where css_put(wb->blkcg_css) is called before blkcg_unpin_online(wb->blkcg_css). If css_put() drops the final reference, the blkcg structure can be freed asynchronously by the cgroup framework before blkcg_unpin_online() attempts to dereference it to access the online_pin member. This local vulnerability requires no user interaction and can be triggered during normal cgroup/writeback lifecycle events. The fix involves reordering the calls to ensure the blkcg remains pinned until all dereferences are complete. Patches have been released for multiple stable kernel branches including 4.19, 6.6, 6.12, 6.18, 6.19, and 7.0.

Affected products

  • Linux Linux Kernel 4.19 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1

Timeline

  • 2026-04-13: disclosed: Initial patch submission by Breno Leitao
  • 2026-04-24: advisory: CVE-2026-31586 published
  • 2026-04-27: patched: Commits merged into stable trees by Greg Kroah-Hartman

References

Related threats