PT-2026-98614 · Linux · Linux

CVE-2026-97950

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
configfs: pin the symlink target's dirent instead of chasing ->ci dentry
create link() reads the target's configfs dirent from item->ci dentry->d fsdata, relying on the item reference taken by get target(). That reference pins the item, not its dentry: the dentry is pinned by DCACHE PERSISTENT, which configfs remove dir() releases via simple rmdir() while the item is still alive. A symlink racing with rmdir of its target can therefore find ->ci dentry freed and its dirent released, triggering WARN ON(!atomic read(&sd->s count)) in configfs get().
Take the dirent in get target() as well, under ->d lock and atomically with the item reference, and pass it down to create link(). A hashed dentry has not been killed yet, so its ->d fsdata reference keeps the dirent alive there.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97950

Produtos afetados

Linux