PT-2026-98635 · Linux · Linux

CVE-2026-97971

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
nstree: check listing permission before taking a namespace reference
legitimize ns() takes a reference on the candidate namespace before may list ns() has decided whether the caller may see it. The free(ns put) cleanup on the denied path can drop the last reference to a mount namespace while we still hold the rcu read lock, and put mnt ns() may sleep there. This is the same problem commit 2ec2aff3c8e2 ("ns: make sure reference are dropped outside of rcu lock") fixed for the put user() path. Neither ns requested() nor may list ns() needs a reference, both only look at the namespace type and at the caller's own namespaces, so do the checks first and take the reference last.
Splat:
Voluntary context switch within RCU read-side critical section! WARNING: kernel/rcu/tree plugin.h:332 at rcu note context switch+0x238/0x2a0, CPU#5: a/3442 CPU: 5 UID: 1000 PID: 3442 Comm: a Not tainted 7.0.0-30-generic #30-Ubuntu PREEMPT(lazy) RIP: 0010:rcu note context switch+0x238/0x2a0 Call Trace: schedule+0xcf/0x650 schedule+0x27/0x90 schedule preempt disabled+0x15/0x30 mutex lock.constprop.0+0x550/0xaf0 mutex lock slowpath+0x13/0x20 mutex lock+0x3b/0x50 exp funnel lock+0xb2/0x260 synchronize rcu expedited+0xe7/0x220 namespace unlock+0x26a/0x320 put mnt ns+0xd3/0x120 mntns put+0xe/0x20 do listns+0x13e/0x560 do sys listns+0x126/0x2d0 x64 sys listns+0x20/0x30 x64 sys call+0x2366/0x2390 do syscall 64+0x105/0x5a0 entry SYSCALL 64 after hwframe+0x76/0x7e

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97971

Produtos afetados

Linux