Incomplete cleanup in Linux kernel - CVE-2026-90182
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to incomplete cleanup of delay state in the blk-iocost policy-data free handler when freeing I/O cost policy data after a block cgroup enters a delay state. A local user can trigger policy-data cleanup after the delay state is set to cause a denial of service.
The stale congestion state applies to every task in the affected block cgroup and its descendants.