PT-2026-98602 · Linux · Linux

CVE-2026-97938

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
reboot: fix cad pid use-after-free race
cad pid is a single kernel-wide struct pid pointer. proc do cad pid() reads it and passes it to pid vnr() without protecting the lifetime of the referenced struct pid. A concurrent writer can replace cad pid and drop the final reference to the old struct pid after the reader has loaded the pointer but before pid vnr() has finished dereferencing it, causing a use-after-free.
kill cad pid() has the same lifetime race when it passes cad pid to kill pid().
At the time this issue was reported, an unprivileged user could reach the sysctl through user and PID namespaces because cad pid was registered in pid table[]. Moving cad pid back to the global reboot sysctl table corrected that namespace and permission mismatch, but did not fix the underlying lifetime race.
Fix this by treating cad pid as an RCU-protected pointer at both read sites and by waiting for a grace period before dropping the old reference on the write side.
call rcu(&old pid->rcu, ...) cannot be used here because free pid() also queues pid->rcu; queueing the same rcu head twice can corrupt the RCU callback list.
Original KASAN crash stack: kernel/pid.c:545 pid nr ns() # reads freed pid->level kernel/pid.c:556 pid vnr() # calls pid nr ns() kernel/pid.c:775 proc do cad pid() # calls pid vnr(cad pid)
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97938

Produtos afetados

Linux