PT-2026-98602 · Linux · Linux
CVE-2026-97938
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
reboot: fix cad pid use-after-free race
cad pid is a single kernel-wide struct pid pointer. proc do cad pid()
reads it and passes it to pid vnr() without protecting the lifetime of
the referenced struct pid. A concurrent writer can replace cad pid and
drop the final reference to the old struct pid after the reader has
loaded the pointer but before pid vnr() has finished dereferencing it,
causing a use-after-free.
kill cad pid() has the same lifetime race when it passes cad pid to
kill pid().
At the time this issue was reported, an unprivileged user could reach the
sysctl through user and PID namespaces because cad pid was registered in
pid table[]. Moving cad pid back to the global reboot sysctl table
corrected that namespace and permission mismatch, but did not fix the
underlying lifetime race.
Fix this by treating cad pid as an RCU-protected pointer at both read
sites and by waiting for a grace period before dropping the old reference
on the write side.
call rcu(&old pid->rcu, ...) cannot be used here because free pid()
also queues pid->rcu; queueing the same rcu head twice can corrupt the
RCU callback list.
Original KASAN crash stack:
kernel/pid.c:545 pid nr ns() # reads freed pid->level
kernel/pid.c:556 pid vnr() # calls pid nr ns()
kernel/pid.c:775 proc do cad pid() # calls pid vnr(cad pid)
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux