blk-cgroup: fix UAF in __blkcg_rstat_flush()
Published Jul 19, 2026
7.8
HIGHCVSS 3.1
EPSS 0.13%
Description
When multiple blkgs in the same blkcg are released concurrently, a use-after-free can occur. The race happens when one blkg's __blkcg_rstat_flush() removes another blkg's iostat entries via llist_del_all(). The second blkg sees an empty list and proceeds to free itself while the first is still iterating over its entries.
Move the flush from __blkg_release() (RCU callback) to blkg_release() (before call_rcu). This ensures the RCU grace period waits for any concurrent flush's rcu_read_lock() section to complete before freeing.
Affected products
-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.3.9StatusaffectedConstraints<6.4
- Version
-
- Version 6.4StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.4
- Version 6.12.95StatusunaffectedConstraints<=6.12.*
- Version 6.18.38StatusunaffectedConstraints<=6.18.*
- Version 6.6.144StatusunaffectedConstraints<=6.6.*
- Version 7.1.3StatusunaffectedConstraints<=7.1.*
- Version 7.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 6.3.9 · < 6.4
- ≥ 6.4.1 · < 6.6.144
- ≥ 6.7 · < 6.12.95
- ≥ 6.13 · < 6.18.38
- ≥ 6.19 · < 7.1.3
- 6.4
- 6.4
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.163.1.el8_10
Fixed · RHSA-2026:67468
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.163.1.rt7.504.el8_10
Fixed · RHSA-2026:67469
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.163.1.el8_10 | Fixed | RHSA-2026:67468 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.163.1.rt7.504.el8_10 | Fixed | RHSA-2026:67469 |
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-63802 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2502251 Issue Tracking
- https://git.kernel.org/stable/c/0ab5ee5a1badb58cbb2242617cb01a4972b1f2a2 Patch
- https://git.kernel.org/stable/c/5e5b7f2ef854936e95dceb6a2fdfefcb7152d2c6 Patch
- https://git.kernel.org/stable/c/96e545410c4f74c89d496c1d5d9ef8d08f14368b Patch
- https://git.kernel.org/stable/c/afebe44facc48a61761e885bbb7f0380d4a603ec Patch
- https://git.kernel.org/stable/c/bbebd9425cad3573d1527441753899b926525a0f Patch
- https://lore.kernel.org/linux-cve-announce/2026071901-CVE-2026-63802-1c53@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-63802
- https://www.cve.org/CVERecord?id=CVE-2026-63802
Change history (0)
No recorded changes yet.