Tracker / CVE-2026-63802
CVE-2026-63802
High 7.8
In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix UAF in __blkcg_rstat_flush() When multiple blkgs in the same blkcg are released concurrently, a use-after-free can occur. The race happens when one blkg's __blkcg_rstat_flush() removes another blkg's iostat entries via llist_del_all(). The second blkg sees an empty list and proceeds to free itself while the first is still iterating over its entries. Move the flush from __blkg_release() (RCU callback) to blkg_release() (before call_rcu). This ensures the RCU grace period waits for any concurrent flush's rcu_read_lock() section to complete before freeing.
Affected products and versions
| linux | linux_kernel |
|---|---|
| linux | linux_kernel · 6.13 → 6.18.38 |
| linux | linux_kernel · 6.19 → 7.1.3 |
| linux | linux_kernel · 6.3.9 → 6.4 |
| linux | linux_kernel · 6.4.1 → 6.6.144 |
| linux | linux_kernel · 6.7 → 6.12.95 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.