{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  blk-cgroup: fix race between policy activation and blkg destruction  When switching an IO scheduler on a block device, blkcg_activate_policy() allocates blkg_policy_data (pd) for all blkgs attached to the queue. However, blkcg_activate_policy() may race with concurrent blkcg deletion, leading to use-after-free and memory leak issues.  The use-after-free occurs in the following race:  T1 (blkcg_activate_policy):   - Successfully allocates pd for blkg1 (loop0-\u003equeue, blkcgA)   - Fails to allocate pd for blkg2 (loop0-\u003equeue, blkcgB)   - Enters the enomem rollback path to release blkg1 resources  T2 (blkcg deletion):   - blkcgA is deleted concurrently   - blkg1 is freed via blkg_free_workfn()   - blkg1-\u003epd is freed  T1 (continued):   - Rollback path accesses blkg1-\u003epd-\u003eonline after pd is freed   - Triggers use-after-free  In addition, blkg_free_workfn() frees pd before removing the blkg from q-\u003eblkg_list. This allows blkcg_activate_policy() to allocate a new pd for a blkg that is being destroyed, leaving the newly allocated pd unreachable when the blkg is finally freed.  Fix these races by extending blkcg_mutex coverage to serialize blkcg_activate_policy() rollback and blkg destruction, ensuring pd lifecycle is synchronized with blkg list visibility.",
  "id": "DEBIAN-CVE-2026-90326",
  "modified": "2026-09-19T22:47:41.166127705Z",
  "published": "2026-09-17T17:17:30.673Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-90326"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-90326"
  ]
}