CVE-2026-68318: pds_core: fix use-after-free on workqueue during remove
In the Linux kernel, the following vulnerability has been resolved:
pdscore: fix use-after-free on workqueue during remove
In pdscremove(), the workqueue is destroyed before pdscteardown() is called. This ordering allows two paths to queue work on the destroyed workqueue:
1. If pdscteardown() -> pdscdevcmdreset() times out, the error path in pdscdevcmdlocked() queues healthwork.
2. A NotifyQ event can trigger the ISR and queue work before freeirq() is called in pdscteardown().
Fix by moving destroyworkqueue() after pdscteardown() so the workqueue outlives every queuer; destroyworkqueue() then flushes any work still pending.
Draining the queued work also requires ordering the teardown so the resources that work touches are freed last:
- In pdscqcqfree(), after freeing the interrupt, cancelworksync() the queue's work and only then clear qcq->intx, so pdscprocessadminq()'s read of qcq->intx for interrupt-credit return cannot race with the clear.
- Free adminqcq before notifyqcq: the shared adminq ISR is released when adminqcq is freed, and the adminq work accesses notifyqcq, so both must be stopped before notifyqcq is freed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Apply the fix so that destroy_workqueue() is called after pdsc_teardown() in pds_core: fix use-after-free on workqueue during remove, ensuring the workqueue (and any queued work such as health_work) is flushed/drained before freeing notifyqcq/adminqcq resources.
Linux kernel (pds_core) workqueue teardown ordering = destroy_workqueue() moved after pdsc_teardown()
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68318?
CVE-2026-68318 has a risk rating of 44.
What type of vulnerability is CVE-2026-68318?
CVE-2026-68318 is classified as a Use After Free vulnerability.
How do I fix CVE-2026-68318?
To fix CVE-2026-68318, ensure that the workqueue is not destroyed before the teardown process is completed.
What systems are affected by CVE-2026-68318?
CVE-2026-68318 affects the Linux kernel components related to pds_core and workqueue management.
When was CVE-2026-68318 published?
CVE-2026-68318 was published on August 10, 2026.