CVE-2026-63804
published 2026-07-19CVE-2026-63804: In the Linux kernel, the following vulnerability has been resolved: gfs2: fix use-after-free in gfs2_qd_dealloc gfs2_qd_dealloc(), called as an RCU callback…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
gfs2: fix use-after-free in gfs2_qd_dealloc
gfs2_qd_dealloc(), called as an RCU callback from gfs2_qd_dispose(),
accesses the superblock object sdp through qd->qd_sbd after freeing qd.
It does so to decrement sd_quota_count and wake up sd_kill_wait.
However, by the time the RCU callback runs, gfs2_put_super() may have
already freed sdp via free_sbd(). This can happen when
gfs2_quota_cleanup() is called during unmount: it disposes of quota
objects via call_rcu() and then waits on sd_kill_wait with a 60-second
timeout. If the timeout expires, or if gfs2_gl_hash_clear() triggers
additional qd_put() calls that schedule more RCU callbacks after the
wait completes, gfs2_put_super() will proceed to free the superblock
while RCU callbacks referencing it are still pending.
Add an rcu_barrier() before free_sbd() in gfs2_put_super() to ensure
all pending RCU callbacks (including gfs2_qd_dealloc) have completed
before the superblock is freed.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= a475c5dd16e57c570113eccba51955b5df8bb052 < 4fe388218826df8607ae41a6305df67db08a9093 | 4fe388218826df8607ae41a6305df67db08a9093 |
| linux | linux | >= a475c5dd16e57c570113eccba51955b5df8bb052 < 8745d9f7e1682c39f0a1578895ac74205e2a6757 | 8745d9f7e1682c39f0a1578895ac74205e2a6757 |
| linux | linux | >= a475c5dd16e57c570113eccba51955b5df8bb052 < b85ef03f726b15047a6fa6d11b639bdf6c0ee4f0 | b85ef03f726b15047a6fa6d11b639bdf6c0ee4f0 |
| linux | linux | >= a475c5dd16e57c570113eccba51955b5df8bb052 < 9d0d5ba20cad661f7f287d4c66d2c19022ce2fd0 | 9d0d5ba20cad661f7f287d4c66d2c19022ce2fd0 |
| linux | linux | >= a475c5dd16e57c570113eccba51955b5df8bb052 < f9c9ec2c319f843b70ecdf939d48b52d189bc081 | f9c9ec2c319f843b70ecdf939d48b52d189bc081 |
| linux | linux_kernel | >= 6.13 < 6.18.38 | 6.18.38 |
| linux | linux_kernel | >= 6.19 < 7.1.3 | 7.1.3 |
| linux | linux_kernel | >= 6.6 < 6.6.144 | 6.6.144 |
| linux | linux_kernel | >= 6.7 < 6.12.95 | 6.12.95 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In the Linux kernel, the following vulnerability has been resolved: gfs2: fix use-after-free in gfs2_qd_dealloc gfs2_qd_dealloc(), called as an RCU callback from gfs2_qd_dispose(), accesses the supe
ghsa_unreviewed·2026-07-19
CVE-2026-63804 In the Linux kernel, the following vulnerability has been resolved: gfs2: fix use-after-free in gfs2_qd_dealloc gfs2_qd_dealloc(), called as an RCU callback from gfs2_qd_dispose(), accesses the supe
In the Linux kernel, the following vulnerability has been resolved:
gfs2: fix use-after-free in gfs2_qd_dealloc
gfs2_qd_dealloc(), called as an RCU callback from gfs2_qd_dispose(),
accesses the superblock object sdp through qd->qd_sbd after freeing qd.
It does so to decrement sd_quota_count and wake up sd_kill_wait.
However, by the time the RCU callback runs, gfs2_put_super() may have
already freed sdp via free_sbd(). This can happen when
gfs2_quota_cleanup() is called during unmount: it disposes of quota
objects via call_rcu() and then waits on sd_kill_wait with a 60-second
timeout. If the timeout expires, or if gfs2_gl_hash_clear() triggers
additional qd_put() calls that schedule more RCU callbacks after the
wait completes, gfs2_put_super() will proceed to free the superblock
while RC
Red Hat
kernel: gfs2: fix use-after-free in gfs2_qd_dealloc
vendor_redhat·2026-07-19·CVSS 5.5
CVE-2026-63804 [MEDIUM] CWE-825 kernel: gfs2: fix use-after-free in gfs2_qd_dealloc
kernel: gfs2: fix use-after-free in gfs2_qd_dealloc
In the Linux kernel, the following vulnerability has been resolved:
gfs2: fix use-after-free in gfs2_qd_dealloc
gfs2_qd_dealloc(), called as an RCU callback from gfs2_qd_dispose(),
accesses the superblock object sdp through qd->qd_sbd after freeing qd.
It does so to decrement sd_quota_count and wake up sd_kill_wait.
However, by the time the RCU callback runs, gfs2_put_super() may have
already freed sdp via free_sbd(). This can happen when
gfs2_quota_cleanup() is called during unmount: it disposes of quota
objects via call_rcu() and then waits on sd_kill_wait with a 60-second
timeout. If the timeout expires, or if gfs2_gl_hash_clear() triggers
additional qd_put() calls that schedule more RCU callbacks after the
wait completes, gfs2_put_su
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/4fe388218826df8607ae41a6305df67db08a9093https://git.kernel.org/stable/c/8745d9f7e1682c39f0a1578895ac74205e2a6757https://git.kernel.org/stable/c/9d0d5ba20cad661f7f287d4c66d2c19022ce2fd0https://git.kernel.org/stable/c/b85ef03f726b15047a6fa6d11b639bdf6c0ee4f0https://git.kernel.org/stable/c/f9c9ec2c319f843b70ecdf939d48b52d189bc081
2026-07-19
Published