PT-2026-98602 · Linux · Linux

CVE-2026-97938

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
reboot: fix cad pid use-after-free race
cad pid is a single kernel-wide struct pid pointer. proc do cad pid() reads it and passes it to pid vnr() without protecting the lifetime of the referenced struct pid. A concurrent writer can replace cad pid and drop the final reference to the old struct pid after the reader has loaded the pointer but before pid vnr() has finished dereferencing it, causing a use-after-free.
kill cad pid() has the same lifetime race when it passes cad pid to kill pid().
At the time this issue was reported, an unprivileged user could reach the sysctl through user and PID namespaces because cad pid was registered in pid table[]. Moving cad pid back to the global reboot sysctl table corrected that namespace and permission mismatch, but did not fix the underlying lifetime race.
Fix this by treating cad pid as an RCU-protected pointer at both read sites and by waiting for a grace period before dropping the old reference on the write side.
call rcu(&old pid->rcu, ...) cannot be used here because free pid() also queues pid->rcu; queueing the same rcu head twice can corrupt the RCU callback list.
Original KASAN crash stack: kernel/pid.c:545 pid nr ns() # reads freed pid->level kernel/pid.c:556 pid vnr() # calls pid nr ns() kernel/pid.c:775 proc do cad pid() # calls pid vnr(cad pid)
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97938

Affected Products

Linux