{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-64378",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-07-19T15:36:31.784Z",
        "datePublished": "2026-07-25T08:50:29.006Z",
        "dateUpdated": "2026-08-17T04:54:29.511Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-17T04:54:29.511Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwriteback: fix race between cgroup_writeback_umount() and inode_switch_wbs()\n\nWhen a container exits, the following BUG_ON() is occasionally triggered:\n\n==================================================================\n VFS: Busy inodes after unmount of sdb (ext4)\n ------------[ cut here ]------------\n kernel BUG at fs/super.c:695!\n CPU: 3 PID: 6 Comm: containerd-shim Tainted: G OE K 6.6 #1\n pstate: 63400009 (nZCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n pc : generic_shutdown_super+0xf0/0x100\n lr : generic_shutdown_super+0xf0/0x100\n Call trace:\n  generic_shutdown_super+0xf0/0x100\n  kill_block_super+0x20/0x48\n  ext4_kill_sb+0x28/0x60\n  deactivate_locked_super+0x54/0x130\n  deactivate_super+0x84/0xa0\n  cleanup_mnt+0xa4/0x140\n  __cleanup_mnt+0x18/0x28\n  task_work_run+0x78/0xe0\n  do_notify_resume+0x204/0x240\n==================================================================\n\nThe root cause is a race between cgroup_writeback_umount() and\ninode_switch_wbs()/cleanup_offline_cgwb(). There is a window between\ninode_prepare_wbs_switch() returning true and the subsequent\nwb_queue_isw() call. Following is the process that triggers the issue:\n\n      CPU A (umount)           |          CPU B (writeback)\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n                                 inode_switch_wbs/cleanup_offline_cgwb\n                                  atomic_inc(&isw_nr_in_flight)\n                                  inode_prepare_wbs_switch\n                                   -> passes SB_ACTIVE check\n                                   __iget(inode)\n generic_shutdown_super\n  sb->s_flags &= ~SB_ACTIVE\n  cgroup_writeback_umount(sb)\n   smp_mb()\n   atomic_read(&isw_nr_in_flight)\n   rcu_barrier()\n    -> no pending RCU callbacks\n   flush_workqueue(isw_wq)\n    -> nothing queued, returns\n  evict_inodes(sb)\n   -> Inode skipped as isw still holds a ref.\n  sop->put_super(sb)\n   /* destroys percpu counters */\n  -> VFS: Busy inodes after unmount!\n                                  wb_queue_isw()\n                                   queue_work(isw_wq, ...)\n                                  /* later in work function */\n                                  inode_switch_wbs_work_fn\n                                   process_inode_switch_wbs\n                                    iput() -> evict\n                                     percpu_counter_dec() // UAF!\n\nFix this by extending the RCU read-side critical section in\ninode_switch_wbs() and cleanup_offline_cgwb() to cover from\ninode_prepare_wbs_switch() through wb_queue_isw().  Since there is\nno sleep in this window, rcu_read_lock() can be used.  Then add a\nsynchronize_rcu() in cgroup_writeback_umount() before the existing\nrcu_barrier(), so that all in-flight switchers that have passed the\nSB_ACTIVE check have completed queue_work() before flush_workqueue()\nis called.\n\nThe existing rcu_barrier() is intentionally retained so this fix can\nbe backported unchanged to stable kernels (5.10.y, 6.6.y, ...) that\nstill queue switches via queue_rcu_work(). It is a no-op on current\nmainline (since commit e1b849cfa6b6 (\"writeback: Avoid contention on\nwb->list_lock when switching inodes\")) and is removed in a follow-up\npatch."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerability is reached through local filesystem writes, cgroup teardown, and mount-namespace or filesystem unmount paths; no network protocol directly reaches the race.\nAC:L - An attacker can churn cgroup writeback switches while repeatedly triggering container or mount teardown, controlling both racing activities and amplifying the timing window.\nPR:L - A basic local or container user can dirty writable files and initiate its own cgroup or namespace teardown; lifecycle infrastructure can perform the privileged final unmount automatically.\nUI:N - The attacker can generate the writeback state and trigger teardown without requiring another user to perform an action.\nS:U - The resulting corruption affects the same host kernel security authority and does not inherently cross a VM or hardware isolation boundary.\nC:H - The delayed worker can access superblock-private state after it and its per-CPU counters have been freed, creating an exploitable use-after-free capable of exposing arbitrary kernel memory.\nI:H - The freed superblock and per-CPU counter pointers are subsequently dereferenced and modified, potentially providing attacker-influenced kernel writes and control-flow hijacking.\nA:H - The race demonstrably triggers the busy-inode BUG_ON, and configurations continuing past that check encounter a use-after-free capable of causing an oops or kernel panic."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/fs-writeback.c"
                    ],
                    "versions": [
                        {
                            "version": "a1a0e23e49037c23ea84bc8cc146a03584d13577",
                            "lessThan": "087d5b8b501c570f84bf655164e6698c3ce146e0",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a1a0e23e49037c23ea84bc8cc146a03584d13577",
                            "lessThan": "3c9c9648f77e4d14e50676bc51c2174ba9c8d361",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a1a0e23e49037c23ea84bc8cc146a03584d13577",
                            "lessThan": "5c3265f3252b2ee50707adaaa3f9bd0df3df72de",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a1a0e23e49037c23ea84bc8cc146a03584d13577",
                            "lessThan": "c923cc3cb5cd8945ceaf08252754110643446593",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a1a0e23e49037c23ea84bc8cc146a03584d13577",
                            "lessThan": "685fc15a410885b6d4dee64de0dce721b9428b12",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a1a0e23e49037c23ea84bc8cc146a03584d13577",
                            "lessThan": "53eeaf4d63068dbc7708b0c7adb20151c812feca",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a1a0e23e49037c23ea84bc8cc146a03584d13577",
                            "lessThan": "cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "c5cbbec54fe71c4de2d34f8c0ec8fbfdd7f17339",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "4.4.5",
                            "lessThan": "4.5",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/fs-writeback.c"
                    ],
                    "versions": [
                        {
                            "version": "4.5",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "4.5",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.261",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.178",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.145",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.96",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.39",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.1.4",
                            "lessThanOrEqual": "7.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.2",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.5",
                                    "versionEndExcluding": "5.10.261"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.5",
                                    "versionEndExcluding": "6.1.178"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.5",
                                    "versionEndExcluding": "6.6.145"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.5",
                                    "versionEndExcluding": "6.12.96"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.5",
                                    "versionEndExcluding": "6.18.39"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.5",
                                    "versionEndExcluding": "7.1.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.5",
                                    "versionEndExcluding": "7.2"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.4.5"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/087d5b8b501c570f84bf655164e6698c3ce146e0"
                },
                {
                    "url": "https://git.kernel.org/stable/c/3c9c9648f77e4d14e50676bc51c2174ba9c8d361"
                },
                {
                    "url": "https://git.kernel.org/stable/c/5c3265f3252b2ee50707adaaa3f9bd0df3df72de"
                },
                {
                    "url": "https://git.kernel.org/stable/c/c923cc3cb5cd8945ceaf08252754110643446593"
                },
                {
                    "url": "https://git.kernel.org/stable/c/685fc15a410885b6d4dee64de0dce721b9428b12"
                },
                {
                    "url": "https://git.kernel.org/stable/c/53eeaf4d63068dbc7708b0c7adb20151c812feca"
                },
                {
                    "url": "https://git.kernel.org/stable/c/cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d"
                }
            ],
            "title": "writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}