PatchSiren cyber security CVE debrief
CVE-2026-64378 Linux CVE debrief
A race condition vulnerability in the Linux kernel's writeback subsystem can lead to use-after-free and potential privilege escalation. The vulnerability is caused by a race between cgroup_writeback_umount() and inode_switch_wbs()/cleanup_offline_cgwb(). This can lead to a use-after-free vulnerability and potential privilege escalation. Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems should review and apply the provided patches to prevent potential exploitation.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-25
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-07-25
- Advisory updated
- 2026-09-08
Who should care
Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems. Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems should review and apply the provided patches to prevent potential exploitation.
Why it matters
A race condition vulnerability in the Linux kernel's writeback subsystem can lead to use-after-free and potential privilege escalation. Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems should review and apply the provided patches to prevent potential exploitation.
- Potential privilege escalation
- Use-after-free vulnerability in the Linux kernel
- Denial of service (DoS) via system crash
Technical summary
The vulnerability is caused by a race between cgroup_writeback_umount() and inode_switch_wbs()/cleanup_offline_cgwb(). This can lead to a use-after-free vulnerability and potential privilege escalation. The vulnerability is caused by a race between cgroup_writeback_umount() and inode_switch_wbs()/cleanup_offline_cgwb(). This can lead to a use-after-free vulnerability and potential privilege escalation. Fix this by extending the RCU read-side critical section in inode_switch_wbs() and cleanup_offline_cgwb() to cover from inode_prepare_wbs_switch() through wb_queue_isw().
Defensive priority
High
Recommended defensive actions
- Review and apply the provided patches to the Linux kernel
- Ensure that the Linux kernel is updated to a version that includes the fix
- Monitor system logs for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is caused by a race between cgroup_writeback_umount() and inode_switch_wbs()/cleanup_offline_cgwb(). The root cause is a race between cgroup_writeback_umount() and inode_switch_wbs()/cleanup_offline_cgwb(). There is a window between inode_prepare_wbs_switch() returning true and the subsequent wb_queue_isw() call. Following is the process that triggers the issue: CPU A (umount) | CPU B (writeback) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ inode_switch_wbs/cleanup_offline_cgwb atomic_inc(&
Sources and references
Verified primary and authoritative sources
-
CVE-2026-64378 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-64378
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-64378 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64378
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/087d5b8b501c570f84bf655164e6698c3ce146e0
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3c9c9648f77e4d14e50676bc51c2174ba9c8d361
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/53eeaf4d63068dbc7708b0c7adb20151c812feca
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5c3265f3252b2ee50707adaaa3f9bd0df3df72de
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/685fc15a410885b6d4dee64de0dce721b9428b12
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c923cc3cb5cd8945ceaf08252754110643446593
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.