gfs2: fix use-after-free in gfs2_qd_dealloc
Summary
| CVE | CVE-2026-63804 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-19 12:16:53 UTC |
| Updated | 2026-07-19 12:16:53 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: gfs2: fix use-after-free in gfs2_qd_dealloc gfs2_qd_dealloc(), called as an RCU callback from gfs2_qd_dispose(), accesses the superblock object sdp through qd->qd_sbd after freeing qd. It does so to decrement sd_quota_count and wake up sd_kill_wait. However, by the time the RCU callback runs, gfs2_put_super() may have already freed sdp via free_sbd(). This can happen when gfs2_quota_cleanup() is called during unmount: it disposes of quota objects via call_rcu() and then waits on sd_kill_wait with a 60-second timeout. If the timeout expires, or if gfs2_gl_hash_clear() triggers additional qd_put() calls that schedule more RCU callbacks after the wait completes, gfs2_put_super() will proceed to free the superblock while RCU callbacks referencing it are still pending. Add an rcu_barrier() before free_sbd() in gfs2_put_super() to ensure all pending RCU callbacks (including gfs2_qd_dealloc) have completed before the superblock is freed. |
Risk And Classification
EPSS: 0.001680000 probability, percentile 0.063820000 (date 2026-07-20)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected a475c5dd16e57c570113eccba51955b5df8bb052 4fe388218826df8607ae41a6305df67db08a9093 git | Not specified |
| CNA | Linux | Linux | affected a475c5dd16e57c570113eccba51955b5df8bb052 8745d9f7e1682c39f0a1578895ac74205e2a6757 git | Not specified |
| CNA | Linux | Linux | affected a475c5dd16e57c570113eccba51955b5df8bb052 b85ef03f726b15047a6fa6d11b639bdf6c0ee4f0 git | Not specified |
| CNA | Linux | Linux | affected a475c5dd16e57c570113eccba51955b5df8bb052 9d0d5ba20cad661f7f287d4c66d2c19022ce2fd0 git | Not specified |
| CNA | Linux | Linux | affected a475c5dd16e57c570113eccba51955b5df8bb052 f9c9ec2c319f843b70ecdf939d48b52d189bc081 git | Not specified |
| CNA | Linux | Linux | affected 6.6 | Not specified |
| CNA | Linux | Linux | unaffected 6.6 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.144 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.95 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.38 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.3 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/f9c9ec2c319f843b70ecdf939d48b52d189bc081 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b85ef03f726b15047a6fa6d11b639bdf6c0ee4f0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4fe388218826df8607ae41a6305df67db08a9093 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/8745d9f7e1682c39f0a1578895ac74205e2a6757 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9d0d5ba20cad661f7f287d4c66d2c19022ce2fd0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.