A vulnerability was found in Linux Kernel up to 6.6.143/6.12.94/6.18.37/7.1.2. It has been declared as very critical. Affected is the function
__blkcg_rstat_flush of the component Blk-Cgroup. The manipulation results in use after free.
This vulnerability was named CVE-2026-63802. The attack may be performed from remote. There is no available exploit.