PT-2026-98614 · Linux · Linux
CVE-2026-97950
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
configfs: pin the symlink target's dirent instead of chasing ->ci dentry
create link() reads the target's configfs dirent from
item->ci dentry->d fsdata, relying on the item reference taken by
get target(). That reference pins the item, not its dentry: the dentry is
pinned by DCACHE PERSISTENT, which configfs remove dir() releases via
simple rmdir() while the item is still alive. A symlink racing with rmdir
of its target can therefore find ->ci dentry freed and its dirent
released, triggering WARN ON(!atomic read(&sd->s count)) in configfs get().
Take the dirent in get target() as well, under ->d lock and atomically
with the item reference, and pass it down to create link(). A hashed
dentry has not been killed yet, so its ->d fsdata reference keeps the
dirent alive there.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux