PT-2026-90276 · Linux · Linux

CVE-2026-89560

·

Publicado

2026-09-11

·

Atualizado

2026-09-11

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
landlock: Require LANDLOCK ACCESS FS MAKE REG for whiteout creation
Whiteout objects are used in the upper layer of an OverlayFS to indicate that the file with this name does not exist in the unified view, even if it is present in one of the lower layer file systems.
For the userspace implementations of OverlayFS (fuse-overlayfs), whiteout objects can be created from userspace as well:
  • mknod(2) with S IFCHR and makedev(0, 0)
  • renameat2(2) with RENAME WHITEOUT, creating the whiteout in the old place of the moved file.
This commit guards whiteout creation in both of these cases with LANDLOCK ACCESS FS MAKE REG. Whiteout objects are not considered character devices and are not bound to a driver.
LANDLOCK ACCESS FS MAKE REG describes the same permission class as a whiteout object: creating one is the only S IFCHR creation that the VFS exempts from CAP MKNOD, so it is as unprivileged as creating a regular file, while LANDLOCK ACCESS FS MAKE CHAR and LANDLOCK ACCESS FS MAKE BLOCK keep meaning the creation of devices that expose a kernel interface [1].
For the mknod(2) case, introduce a Landlock erratum. The creation of whiteout objects through mknod(2) was previously guarded using LANDLOCK ACCESS FS MAKE CHAR, and it is now guarded using LANDLOCK ACCESS FS MAKE REG.
For the renameat2(2) case, fix a bug: Before this commit, renameat2(2) with RENAME WHITEOUT would create a directory entry even when all LANDLOCK ACCESS FS MAKE * rights were denied.
This does not affect normal renames within layered OverlayFS mounts: When doing a regular rename() on a mounted fuse-overlayfs, it is the fuse-overlayfs daemon that exercises renameat2() with RENAME WHITEOUT, and only the Landlock domain of that daemon is checked there.
Depends-on: 49c9e09d9610 ("landlock: Fix handling of disconnected directories") Depends-on: fe72ce6710cb ("landlock: Add errata documentation section") [mic: Record why LANDLOCK ACCESS FS MAKE REG is the matching right, and add link(2) to the user doc]
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-89560

Produtos afetados

Linux