{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-31586", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2026-03-09T15:48:24.120Z", "datePublished": "2026-04-24T14:42:14.937Z", "dateUpdated": "2026-08-05T12:23:37.101Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:23:37.101Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: blk-cgroup: fix use-after-free in cgwb_release_workfn()\n\ncgwb_release_workfn() calls css_put(wb->blkcg_css) and then later accesses\nwb->blkcg_css again via blkcg_unpin_online(). If css_put() drops the last\nreference, the blkcg can be freed asynchronously (css_free_rwork_fn ->\nblkcg_css_free -> kfree) before blkcg_unpin_online() dereferences the\npointer to access blkcg->online_pin, resulting in a use-after-free:\n\n BUG: KASAN: slab-use-after-free in blkcg_unpin_online (./include/linux/instrumented.h:112 ./include/linux/atomic/atomic-instrumented.h:400 ./include/linux/refcount.h:389 ./include/linux/refcount.h:432 ./include/linux/refcount.h:450 block/blk-cgroup.c:1367)\n Write of size 4 at addr ff11000117aa6160 by task kworker/71:1/531\n Workqueue: cgwb_release cgwb_release_workfn\n Call Trace:\n \n blkcg_unpin_online (./include/linux/instrumented.h:112 ./include/linux/atomic/atomic-instrumented.h:400 ./include/linux/refcount.h:389 ./include/linux/refcount.h:432 ./include/linux/refcount.h:450 block/blk-cgroup.c:1367)\n cgwb_release_workfn (mm/backing-dev.c:629)\n process_scheduled_works (kernel/workqueue.c:3278 kernel/workqueue.c:3385)\n\n Freed by task 1016:\n kfree (./include/linux/kasan.h:235 mm/slub.c:2689 mm/slub.c:6246 mm/slub.c:6561)\n css_free_rwork_fn (kernel/cgroup/cgroup.c:5542)\n process_scheduled_works (kernel/workqueue.c:3302 kernel/workqueue.c:3385)\n\n** Stack based on commit 66672af7a095 (\"Add linux-next specific files\nfor 20260410\")\n\nI am seeing this crash sporadically in Meta fleet across multiple kernel\nversions. A full reproducer is available at:\nhttps://github.com/leitao/debug/blob/main/reproducers/repro_blkcg_uaf.sh\n\n(The race window is narrow. To make it easily reproducible, inject a\nmsleep(100) between css_put() and blkcg_unpin_online() in\ncgwb_release_workfn(). With that delay and a KASAN-enabled kernel, the\nreproducer triggers the splat reliably in less than a second.)\n\nFix this by moving blkcg_unpin_online() before css_put(), so the\ncgwb's CSS reference keeps the blkcg alive while blkcg_unpin_online()\naccesses it." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerable path is reached by local cgroup/writeback activity: creating/removing cgroup v2 subgroups, moving a task into them, and dirtying files on a block-backed filesystem. There is no network or physical packet/device entry point.\nAC:L - Although the timing window is narrow, the attacker can repeatedly drive both cgroup teardown and cgwb creation/release through cgroup churn and buffered writes. Per the scoring rule for attacker-driven races and UAFs, this is low complexity.\nPR:L - The attacker needs local ability to manipulate a delegated cgroup subtree and run file I/O, which is available to low-privileged users in reasonable delegated cgroup v2 or container/user-slice deployments. It does not require real init-namespace root in those scenarios.\nUI:N - No victim action is required once the attacker has local execution and cgroup access. The attacker triggers creation, writeback, and removal directly.\nS:U - The vulnerability is in the host kernel’s cgroup/writeback lifetime management and impacts the same kernel security authority. Standard local kernel privilege escalation is scored as unchanged scope.\nC:H - The bug is a use-after-free of a freed blkcg object after css_put can lead to blkcg_css_free and kfree before blkcg_unpin_online dereferences it. Kernel UAFs are scored high for confidentiality because reclaimed slab contents can be abused for memory disclosure primitives.\nI:H - The immediate UAF performs a refcount decrement/write through freed memory, and reclaimed-object corruption can plausibly be shaped into broader kernel heap corruption or control-flow compromise. Kernel UAF memory corruption is scored high for integrity.\nA:H - The reported failure is a slab-use-after-free in a kernel worker and can cause an oops, panic, or persistent kernel instability. Repeated local triggering makes availability impact high." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "mm/backing-dev.c" ], "versions": [ { "version": "59b57717fff8b562825d9d25e0180ad7e8048ca9", "lessThan": "23acef4156c260e8598397a1a2e8b3a23e919893", "status": "affected", "versionType": "git" }, { "version": "59b57717fff8b562825d9d25e0180ad7e8048ca9", "lessThan": "1bd36e93b542d9dd020190c6607c6a3663405195", "status": "affected", "versionType": "git" }, { "version": "59b57717fff8b562825d9d25e0180ad7e8048ca9", "lessThan": "740ba1ebb223f137ff088ab74d533a13f9167bd8", "status": "affected", "versionType": "git" }, { "version": "59b57717fff8b562825d9d25e0180ad7e8048ca9", "lessThan": "115a5266749dcde7fe4127e8623d19c752088f69", "status": "affected", "versionType": "git" }, { "version": "59b57717fff8b562825d9d25e0180ad7e8048ca9", "lessThan": "dfc8292a1d6782c76b626315605e0585a5a18447", "status": "affected", "versionType": "git" }, { "version": "59b57717fff8b562825d9d25e0180ad7e8048ca9", "lessThan": "ea3af09eb87d8f8708c66747fcf1a2762902e839", "status": "affected", "versionType": "git" }, { "version": "59b57717fff8b562825d9d25e0180ad7e8048ca9", "lessThan": "50879a3c1faf06e661090015d59e2127255cff27", "status": "affected", "versionType": "git" }, { "version": "59b57717fff8b562825d9d25e0180ad7e8048ca9", "lessThan": "67cb119d32f35e32acd0393bbeb318b2bb1fdafe", "status": "affected", "versionType": "git" }, { "version": "59b57717fff8b562825d9d25e0180ad7e8048ca9", "lessThan": "8f5857be99f1ed1fa80991c72449541f634626ee", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "mm/backing-dev.c" ], "versions": [ { "version": "4.19", "status": "affected" }, { "version": "0", "lessThan": "4.19", "status": "unaffected", "versionType": "semver" }, { "version": "5.10.258", "lessThanOrEqual": "5.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.209", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.175", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.136", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.83", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18.24", "lessThanOrEqual": "6.18.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.19.14", "lessThanOrEqual": "6.19.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.0.1", "lessThanOrEqual": "7.0.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.1", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.19", "versionEndExcluding": "5.10.258" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.19", "versionEndExcluding": "5.15.209" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.19", "versionEndExcluding": "6.1.175" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.19", "versionEndExcluding": "6.6.136" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.19", "versionEndExcluding": "6.12.83" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.19", "versionEndExcluding": "6.18.24" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.19", "versionEndExcluding": "6.19.14" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.19", "versionEndExcluding": "7.0.1" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.19", "versionEndExcluding": "7.1" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/23acef4156c260e8598397a1a2e8b3a23e919893" }, { "url": "https://git.kernel.org/stable/c/1bd36e93b542d9dd020190c6607c6a3663405195" }, { "url": "https://git.kernel.org/stable/c/740ba1ebb223f137ff088ab74d533a13f9167bd8" }, { "url": "https://git.kernel.org/stable/c/115a5266749dcde7fe4127e8623d19c752088f69" }, { "url": "https://git.kernel.org/stable/c/dfc8292a1d6782c76b626315605e0585a5a18447" }, { "url": "https://git.kernel.org/stable/c/ea3af09eb87d8f8708c66747fcf1a2762902e839" }, { "url": "https://git.kernel.org/stable/c/50879a3c1faf06e661090015d59e2127255cff27" }, { "url": "https://git.kernel.org/stable/c/67cb119d32f35e32acd0393bbeb318b2bb1fdafe" }, { "url": "https://git.kernel.org/stable/c/8f5857be99f1ed1fa80991c72449541f634626ee" } ], "title": "mm: blk-cgroup: fix use-after-free in cgwb_release_workfn()", "x_generator": { "engine": "bippy-1.2.0" } } } }