PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64378 Linux CVE debrief

A race condition vulnerability in the Linux kernel's writeback subsystem can lead to use-after-free and potential privilege escalation. The vulnerability is caused by a race between cgroup_writeback_umount() and inode_switch_wbs()/cleanup_offline_cgwb(). This can lead to a use-after-free vulnerability and potential privilege escalation. Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems should review and apply the provided patches to prevent potential exploitation.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-25
Original CVE updated
2026-09-08
Advisory published
2026-07-25
Advisory updated
2026-09-08

Who should care

Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems. Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems should review and apply the provided patches to prevent potential exploitation.

Why it matters

A race condition vulnerability in the Linux kernel's writeback subsystem can lead to use-after-free and potential privilege escalation. Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems should review and apply the provided patches to prevent potential exploitation.

  • Potential privilege escalation
  • Use-after-free vulnerability in the Linux kernel
  • Denial of service (DoS) via system crash

Technical summary

The vulnerability is caused by a race between cgroup_writeback_umount() and inode_switch_wbs()/cleanup_offline_cgwb(). This can lead to a use-after-free vulnerability and potential privilege escalation. The vulnerability is caused by a race between cgroup_writeback_umount() and inode_switch_wbs()/cleanup_offline_cgwb(). This can lead to a use-after-free vulnerability and potential privilege escalation. Fix this by extending the RCU read-side critical section in inode_switch_wbs() and cleanup_offline_cgwb() to cover from inode_prepare_wbs_switch() through wb_queue_isw().

Defensive priority

High

Recommended defensive actions

  • Review and apply the provided patches to the Linux kernel
  • Ensure that the Linux kernel is updated to a version that includes the fix
  • Monitor system logs for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is caused by a race between cgroup_writeback_umount() and inode_switch_wbs()/cleanup_offline_cgwb(). The root cause is a race between cgroup_writeback_umount() and inode_switch_wbs()/cleanup_offline_cgwb(). There is a window between inode_prepare_wbs_switch() returning true and the subsequent wb_queue_isw() call. Following is the process that triggers the issue: CPU A (umount) | CPU B (writeback) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ inode_switch_wbs/cleanup_offline_cgwb atomic_inc(&

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64378 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64378

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64378 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64378

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/087d5b8b501c570f84bf655164e6698c3ce146e0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3c9c9648f77e4d14e50676bc51c2174ba9c8d361

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/53eeaf4d63068dbc7708b0c7adb20151c812feca

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5c3265f3252b2ee50707adaaa3f9bd0df3df72de

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/685fc15a410885b6d4dee64de0dce721b9428b12

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c923cc3cb5cd8945ceaf08252754110643446593

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.