PT-2026-98534 · Linux · Linux

CVE-2026-97594

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
landlock: Fix use-after-free of the source's parent directory
current check refer path() reads old dentry->d parent without holding a reference nor a lock on it, and then dereferences it in collect domain accesses() and in the audit record.
A reference on a child does not pin its parent: d move() reassigns dentry->d parent and drops the reference the child held on its former parent. hook path rename() is not affected because the rename path calls lock rename() before the hook, so the source cannot be reparented under it. hook path link() has no such protection: filename linkat() holds a reference on the source dentry but neither locks nor references its parent, so a concurrent rename(2) can reparent the source while security path link() runs, and the former parent can then be removed and freed while the hook walks it.
A process can trigger this after entering a Landlock domain that handles at least one filesystem access right. The process can then race a linkat(2) loop against rename(2) and rmdir(2):
BUG: KASAN: slab-use-after-free in collect domain accesses+0x278/0x290 Read of size 4 at addr ffff888160bd53f4 by task llrepro2/549 collect domain accesses+0x278/0x290 current check refer path+0x952/0x1120 security path link+0x1be/0x320 filename linkat+0x342/0x6d0 x64 sys linkat+0xfa/0x150 Freed by task 562: kmem cache free+0x139/0x4c0 i callback+0x4b/0x80 rcu core+0x7dc/0x10a0
Take a reference on the dentry selected as the source parent, using dget() for the common-mount-root case and dget parent() otherwise. Release it after the hierarchy walk and synchronous audit logging.
[mic: Clarify the caller, reachability, and reference handling]

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97594

Produtos afetados

Linux