Use-after-free in Linux kernel - CVE-2026-90325
Published: September 18, 2026
Vulnerability identifier: #VU151160
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90325
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free condition.
The vulnerability exists due to a use-after-free in blkcg_activate_policy() when switching I/O schedulers concurrently with blkcg deletion. A local user can race scheduler switching with blkcg deletion to trigger a use-after-free condition.
Affected software
Linux kernel
How to mitigate CVE-2026-90325
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/083b58373463a6e5ee60ecb135269348f68ad7df
- https://git.kernel.org/stable/c/1a267295b1ea6a6477963f3fda84adfecd48fcad
- https://git.kernel.org/stable/c/3d8c3da95c75a4d312e272fc7b4076dd3ba9115c
- https://git.kernel.org/stable/c/5e9220389920f33b6a804d50c548cd0cd1b04634
- https://git.kernel.org/stable/c/7337d012ca3fc3a6a2d1c8e2a19c6d97c38b410d
- https://git.kernel.org/stable/c/b5dae1cd0d8368b4338430ff93403df67f0b8bcc
- https://git.kernel.org/stable/c/d8c872901e6459339374e9eea80aa919176c2ccd