PT-2026-98613 · Linux · Linux

CVE-2026-97949

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
configfs: unhash the dentry before dropping the item in rmdir
configfs get config item() treats a hashed dentry as proof that sd->s element is a live config item. configfs rmdir() breaks that: simple rmdir() leaves the dentry hashed, the last reference to the item is dropped right after, and the dentry is only unhashed by d delete() once ->rmdir() has returned. configfs symlink() resolves its target holding no lock on it, so get target() can land in that window:
BUG: KASAN: slab-use-after-free in config item get+0x26/0x90 get target fs/configfs/symlink.c:128 [inline] configfs symlink+0x4ab/0x1030 fs/configfs/symlink.c:185
Unhash in configfs remove dir(), while the item is still guaranteed to be there. A reference obtained just before that stays harmless, as create link() rechecks CONFIGFS USET DROPPING, already set by configfs detach prep(). Both configfs unregister subsystem() paths d drop() after detaching, so this only makes rmdir match them.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97949

Produtos afetados

Linux