cbcvebase.
CVE-2026-53129
published 2026-06-24

CVE-2026-53129: In the Linux kernel, the following vulnerability has been resolved: fs/mbcache: cancel shrink work before destroying the cache mb_cache_destroy() calls…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
1.9th percentile
In the Linux kernel, the following vulnerability has been resolved: fs/mbcache: cancel shrink work before destroying the cache mb_cache_destroy() calls shrinker_free() and then frees all cache entries and the cache itself, but it does not cancel the pending c_shrink_work work item first. If mb_cache_entry_create() schedules c_shrink_work via schedule_work() and the work item is still pending or running when mb_cache_destroy() runs, mb_cache_shrink_worker() will access the cache after its memory has been freed, causing a use-after-free. This is only reachable by a privileged user (root or CAP_SYS_ADMIN) who can trigger the last put of a mounted ext2/ext4/ocfs2 filesystem. Cancel the work item with cancel_work_sync() before calling shrinker_free(), ensuring the worker has finished and will not be rescheduled before the cache is torn down.

Affected

9 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= c2f3140fe2eceb3a6c1615b2648b9471544881c6 < a88d39a74a208e197c03bffaa2df34de732af19fa88d39a74a208e197c03bffaa2df34de732af19f
linuxlinux>= c2f3140fe2eceb3a6c1615b2648b9471544881c6 < 0e4eff315d799f5842b95872199b0f0fb8ef5f510e4eff315d799f5842b95872199b0f0fb8ef5f51
linuxlinux>= c2f3140fe2eceb3a6c1615b2648b9471544881c6 < b25fd3523bef88fb7ffd4c5b63bbe9c08f73bb4cb25fd3523bef88fb7ffd4c5b63bbe9c08f73bb4c
linuxlinux>= c2f3140fe2eceb3a6c1615b2648b9471544881c6 < d227786ab1119669df4dc333a61510c52047cce4d227786ab1119669df4dc333a61510c52047cce4
linuxlinux_kernel
linuxlinux_kernel>= 4.6 < 6.12.916.12.91
linuxlinux_kernel>= 6.13 < 6.18.336.18.33
linuxlinux_kernel>= 6.19 < 7.0.107.0.10

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.