CVE-2026-68318: pds_core: fix use-after-free on workqueue during remove

Published Aug 10, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

pdscore: fix use-after-free on workqueue during remove

In pdscremove(), the workqueue is destroyed before pdscteardown() is called. This ordering allows two paths to queue work on the destroyed workqueue:

1. If pdscteardown() -> pdscdevcmdreset() times out, the error path in pdscdevcmdlocked() queues healthwork.

2. A NotifyQ event can trigger the ISR and queue work before freeirq() is called in pdscteardown().

Fix by moving destroyworkqueue() after pdscteardown() so the workqueue outlives every queuer; destroyworkqueue() then flushes any work still pending.

Draining the queued work also requires ordering the teardown so the resources that work touches are freed last:

- In pdscqcqfree(), after freeing the interrupt, cancelworksync() the queue's work and only then clear qcq->intx, so pdscprocessadminq()'s read of qcq->intx for interrupt-credit return cannot race with the clear.

- Free adminqcq before notifyqcq: the shared adminq ISR is released when adminqcq is freed, and the adminq work accesses notifyqcq, so both must be stopped before notifyqcq is freed.

Affected Software

1 affected component
Linux Kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Apply the fix so that destroy_workqueue() is called after pdsc_teardown() in pds_core: fix use-after-free on workqueue during remove, ensuring the workqueue (and any queued work such as health_work) is flushed/drained before freeing notifyqcq/adminqcq resources.

    Linux kernel (pds_core) workqueue teardown ordering = destroy_workqueue() moved after pdsc_teardown()

Event History

Aug 10, 2026
CVE Published
via MITRE·12:02 PM
Data Sourced
via MITRE·12:02 PM
Description
Data Sourced
via NVD·01:20 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-68318?

CVE-2026-68318 has a risk rating of 44.

2

What type of vulnerability is CVE-2026-68318?

CVE-2026-68318 is classified as a Use After Free vulnerability.

3

How do I fix CVE-2026-68318?

To fix CVE-2026-68318, ensure that the workqueue is not destroyed before the teardown process is completed.

4

What systems are affected by CVE-2026-68318?

CVE-2026-68318 affects the Linux kernel components related to pds_core and workqueue management.

5

When was CVE-2026-68318 published?

CVE-2026-68318 was published on August 10, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203