Executive brief
A vulnerability in the Linux kernel's filesystem cache management could allow a privileged user to cause a system crash. The issue occurs when the system attempts to clean up memory used by certain filesystems (ext2, ext4, or ocfs2) while a background maintenance task is still running. This results in a 'use-after-free' condition, which typically leads to system instability or a kernel panic.
Technical details
A use-after-free vulnerability exists in fs/mbcache.c in the Linux kernel. The mb_cache_destroy() function frees cache entries and the cache structure itself without first canceling pending c_shrink_work items. If a shrink worker is scheduled or running during cache destruction, it may attempt to access the cache memory after it has been deallocated. This flaw is exploitable only by a local user with root or CAP_SYS_ADMIN privileges who can trigger the final put of a mounted ext2, ext4, or ocfs2 filesystem. The issue has been resolved by adding a cancel_work_sync() call to ensure background tasks complete before memory is freed.
Affected products
- Linux Linux 4.6 to 7.0.10
Timeline
- 2026-03-17: other: Vulnerability fixed in upstream kernel commit
- 2026-06-24: advisory: CVE published