Review reviewHigh

CVE-2026-64378

Linux

In the Linux kernel, the following vulnerability has been resolved: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() When a container exits, the following BUG_ON() is occasionally triggered: ================================================================== VFS: Busy inodes after unmount of sdb (ext4) ------------[ cut here ]------------ kernel BUG at fs/super.c:695! CPU: 3 PID: 6 Comm: containerd-shim Tainted: G OE K 6.6 #1 pstate: 63400009 (nZCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--) pc : generic_shutdown_super+0xf0/0x100 lr : generic_shutdown_super+0xf0/0x10...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() When a container exits, the following BUG_ON() is occasionally triggered: ================================================================== VFS: Busy inodes after unmount of sdb (ext4) ------------[ cut here ]------------ kernel BUG at fs/super.c:695! CPU: 3 PID: 6 Comm: containerd-shim Tainted: G OE K 6.6 #1 pstate: 63400009 (nZCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--) pc : generic_shutdown_super+0xf0/0x100 lr : generic_shutdown_super+0xf0/0x10...

Affected product and versions

Product
Linux
Affected versions
>= a1a0e23e49037c23ea84bc8cc146a03584d13577 < 087d5b8b501c570f84bf655164e6698c3ce146e0, >= a1a0e23e49037c23ea84bc8cc146a03584d13577 < 3c9c9648f77e4d14e50676bc51c2174ba9c8d361, >= a1a0e23e49037c23ea84bc8cc146a03584d13577 < 5c3265f3252b2ee50707adaaa3f9bd0df3df72de, >= a1a0e23e49037c23ea84bc8cc146a03584d13577 < c923cc3cb5cd8945ceaf08252754110643446593, >= a1a0e23e49037c23ea84bc8cc146a03584d13577 < 685fc15a410885b6d4dee64de0dce721b9428b12, >= a1a0e23e49037c23ea84bc8cc146a03584d13577 < 53eeaf4d63068dbc7708b0c7adb20151c812feca, >= a1a0e23e49037c23ea84bc8cc146a03584d13577 < cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d, >= c5cbbec54fe71c4de2d34f8c0ec8fbfdd7f17339, >= 4.4.5 < 4.5, >= 4.5
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2026-64378 — Linux | SECUFOCUS NOW