CVE-2026-63802

Updated on 19 Jul 2026

Severity

7.0 High severity

Details

CVSS score
7.0
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

blk-cgroup: fix UAF in __blkcg_rstat_flush()

When multiple blkgs in the same blkcg are released concurrently, a use-after-free can occur. The race happens when one blkg’s __blkcg_rstat_flush() removes another blkg’s iostat entries via llist_del_all(). The second blkg sees an empty list and proceeds to free itself while the first is still iterating over its entries.

Move the flush from __blkg_release() (RCU callback) to blkg_release() (before call_rcu). This ensures the RCU grace period waits for any concurrent flush’s rcu_read_lock() section to complete before freeing.

Details

Affected packages:
kernel @ 5.14.0 (+4 more)

Fixes

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
AlmaLinux 9.6 ESU Released
18 kernels
  • 5.14.0-570.62.1.el9_6.tuxcare.1.els1
  • 5.14.0-570.62.1.el9_6.tuxcare.1.els2
  • 5.14.0-570.62.1.el9_6.tuxcare.1.els3
  • 5.14.0-570.62.1.el9_6.tuxcare.1.els4
  • 5.14.0-570.62.1.el9_6.tuxcare.1.els5
  • 5.14.0-570.62.1.el9_6.tuxcare.1.els6
  • 5.14.0-570.62.1.el9_6.tuxcare.1.els7
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els1
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els2
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els3
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els4
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els5
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els6
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els7
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els8
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els10
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els11
  • 5.14.0-570.62.1.el9_6.tuxcare.5.els12
Debian 13 Planned
RHEL 8 Planned