« Volver al listado

CVE-2026-93795

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

blk-cgroup: fix leaks and online flag on radix_tree_insert failure

When radix_tree_insert() fails in blkg_create(), the error path has two issues:

Fix by replacing blkg_put() with percpu_ref_kill(), matching the pattern used in blkg_destroy().

Detalles técnicos trazas, registros y código del informe original
1. blkg->online is set to true unconditionally, even when the blkg was
   never fully inserted.  Move the assignment inside the success block.

2. The error path calls blkg_put() without first calling
   percpu_ref_kill().  Because the refcount is still in percpu mode,
   percpu_ref_put() only does this_cpu_sub() without checking for zero,
   so blkg_release() is never triggered.  This permanently leaks the
   blkg memory, its percpu iostat, policy data, the parent blkg
   reference, and the cgroup css reference — the latter preventing the
   cgroup from ever being destroyed.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93795",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7fcf2b033b84e261dca283bc2911aaea4b07b525",
              "lessThan": "0f840db042caee9d2f3dcdcf97d6674f6e4c1e30",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7fcf2b033b84e261dca283bc2911aaea4b07b525",
              "lessThan": "f53945d7c712efe63fadbcc5ffed6370871fd0d3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7fcf2b033b84e261dca283bc2911aaea4b07b525",
              "lessThan": "ada8270ccdb6f212da5eb22614c28ea418746a4a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7fcf2b033b84e261dca283bc2911aaea4b07b525",
              "lessThan": "c3650be82ef6e7af13b79b2d10a7363bdf54aa7f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7fcf2b033b84e261dca283bc2911aaea4b07b525",
              "lessThan": "6e85f02d45b5977c0326a8d854c6db878aa6b34a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7fcf2b033b84e261dca283bc2911aaea4b07b525",
              "lessThan": "4c0d150fb98ea40760611979f4e664c244b20966",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7fcf2b033b84e261dca283bc2911aaea4b07b525",
              "lessThan": "dbbca20764382b4d411ec2918f4e278ffe547acc",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "block/blk-cgroup.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "block/blk-cgroup.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:12.270",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0f840db042caee9d2f3dcdcf97d6674f6e4c1e30",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4c0d150fb98ea40760611979f4e664c244b20966",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6e85f02d45b5977c0326a8d854c6db878aa6b34a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ada8270ccdb6f212da5eb22614c28ea418746a4a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c3650be82ef6e7af13b79b2d10a7363bdf54aa7f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dbbca20764382b4d411ec2918f4e278ffe547acc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f53945d7c712efe63fadbcc5ffed6370871fd0d3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: fix leaks and online flag on radix_tree_insert failure\n\nWhen radix_tree_insert() fails in blkg_create(), the error path has two\nissues:\n\n1. blkg->online is set to true unconditionally, even when the blkg was\n   never fully inserted.  Move the assignment inside the success block.\n\n2. The error path calls blkg_put() without first calling\n   percpu_ref_kill().  Because the refcount is still in percpu mode,\n   percpu_ref_put() only does this_cpu_sub() without checking for zero,\n   so blkg_release() is never triggered.  This permanently leaks the\n   blkg memory, its percpu iostat, policy data, the parent blkg\n   reference, and the cgroup css reference — the latter preventing the\n   cgroup from ever being destroyed.\n\nFix by replacing blkg_put() with percpu_ref_kill(), matching the pattern\nused in blkg_destroy()."
    }
  ],
  "lastModified": "2026-10-03T11:17:49.107",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}