Junglewise Threat Intelligence

CVE-2026-90325: Linux kernel blk-cgroup use-after-free in blkcg_activate_policy

CVE-2026-90325 · Severity: high · CVSS 7.8 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel block I/O cgroup subsystem contains a race condition when switching I/O schedulers on block devices. An attacker or malicious process could exploit this to trigger a use-after-free memory error, potentially leading to privilege escalation, denial of service, or code execution on systems running affected kernel versions.

Technical details

This is a use-after-free vulnerability in the block cgroup (blk-cgroup) subsystem of the Linux kernel. The vulnerability occurs in the blkcg_activate_policy() function when it races with concurrent blkg (block group) destruction. The root cause is a missing check for unhashed blkg objects: during IO scheduler switching, the function attempts to get a reference to a blkg that may have already begun destruction in parallel. The fix adds a check using hlist_unhashed(&blkg->blkcg_node) to detect dying blkg objects and skip processing them, preventing the use-after-free. The vulnerability requires local access or the ability to trigger IO scheduler switches and concurrent blkcg deletion on the affected system. A patch is available in Linux kernel stable branches.

Affected products

  • Linux Linux kernel multiple kernel versions (specific affected versions depend on release branch)

Timeline

  • 2026-09-17: disclosed: CVE-2026-90325 published
  • 2026-09-14: patched: Fix committed to stable branches
  • 2026-08-02: other: Upstream commit authored

References

Related threats