Executive brief
A vulnerability was identified in the Linux kernel's GFS2 file system that could lead to a system crash or unpredictable behavior during the unmounting of a disk. The issue occurs when the system attempts to clean up user quota information while simultaneously shutting down the file system, leading to a 'use-after-free' error. This primarily affects system stability and availability during administrative operations like unmounting a network file system.
Technical details
A use-after-free vulnerability exists in the GFS2 file system within the gfs2_qd_dealloc() function. When gfs2_quota_cleanup() is invoked during unmount, it schedules quota object disposal via call_rcu(). If the 60-second timeout in sd_kill_wait expires or if additional callbacks are queued after the wait, gfs2_put_super() may proceed to free the superblock (sdp) via free_sbd() while RCU callbacks are still pending. These callbacks subsequently attempt to access the freed superblock to decrement sd_quota_count. The fix introduces an rcu_barrier() in gfs2_put_super() to ensure all pending callbacks complete before the superblock memory is reclaimed.
Affected products
- Linux Linux Kernel 6.6 to 6.6.144, 6.12 to 6.12.95, 6.18 to 6.18.38, 7.1 to 7.1.3
Timeline
- 2026-05-01: other: Vulnerability fixed in upstream source code
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/4fe388218826df8607ae41a6305df67db08a9093
- https://git.kernel.org/stable/c/8745d9f7e1682c39f0a1578895ac74205e2a6757
- https://git.kernel.org/stable/c/9d0d5ba20cad661f7f287d4c66d2c19022ce2fd0
- https://git.kernel.org/stable/c/b85ef03f726b15047a6fa6d11b639bdf6c0ee4f0
- https://git.kernel.org/stable/c/f9c9ec2c319f843b70ecdf939d48b52d189bc081