Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-90325NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

blk-cgroup: skip dying blkg in blkcg_activate_policy()

When switching IO schedulers on a block device, blkcg_activate_policy()
can race with concurrent blkcg deletion, leading to a use-after-free in
rcu_accelerate_cbs.

T1: T2:
blkg_destroy
kill(&blkg->refcnt) // blkg->refcnt=1->0
blkg_release // call_rcu(__blkg_release)
...
blkg_free_workfn
->pd_free_fn(pd)
elv_iosched_store
elevator_switch
...
iterate blkg list
blkg_get(blkg) // blkg->refcnt=0->1
list_del_init(&blkg->q_node)
blkg_put(pinned_blkg) // blkg->refcnt=1->0
blkg_release // call_rcu again
rcu_accelerate_cbs // uaf

Fix this by checking hlist_unhashed(&blkg->blkcg_node) before getting
a reference to the blkg. This is the same check used in blkg_destroy()
to detect if a blkg has already been destroyed. If the blkg is already
unhashed, skip processing it since it's being destroyed.
Severity Level
HIGH(7.8)
Published Date
Sep 17, 2026
Last Modified
Sep 18, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.16%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics — Score 7.8 (HIGH)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • Linux Linux >= 81c1188905f88b77743d1fdeeedfc8cb7b67787d and < b5dae1cd0d8368b4338430ff93403df67f0b8bcc
  • Linux Linux >= bfe46d2efe46c5c952f982e2ca94fe2ec5e58e2a and < 083b58373463a6e5ee60ecb135269348f68ad7df
  • Linux Linux >= f1c006f1c6850c14040f8337753a63119bba39b9 and < 1a267295b1ea6a6477963f3fda84adfecd48fcad
  • Linux Linux >= f1c006f1c6850c14040f8337753a63119bba39b9 and < 7337d012ca3fc3a6a2d1c8e2a19c6d97c38b410d
  • Linux Linux >= f1c006f1c6850c14040f8337753a63119bba39b9 and < 3d8c3da95c75a4d312e272fc7b4076dd3ba9115c
  • Linux Linux >= f1c006f1c6850c14040f8337753a63119bba39b9 and < d8c872901e6459339374e9eea80aa919176c2ccd
  • Linux Linux >= f1c006f1c6850c14040f8337753a63119bba39b9 and < 5e9220389920f33b6a804d50c548cd0cd1b04634
  • Linux Linux >= 6.1.16 and < 6.1.17
  • Linux Linux >= 6.2.3 and < 6.2.4
  • Linux Linux >= 6.3
Patched Versions
  • Linux Linux b5dae1cd0d8368b4338430ff93403df67f0b8bcc
  • Linux Linux 083b58373463a6e5ee60ecb135269348f68ad7df
  • Linux Linux 1a267295b1ea6a6477963f3fda84adfecd48fcad
  • Linux Linux 7337d012ca3fc3a6a2d1c8e2a19c6d97c38b410d
  • Linux Linux 3d8c3da95c75a4d312e272fc7b4076dd3ba9115c
  • Linux Linux d8c872901e6459339374e9eea80aa919176c2ccd
  • Linux Linux 5e9220389920f33b6a804d50c548cd0cd1b04634
  • Linux Linux 6.1.17
  • Linux Linux 6.2.4
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.