PT-2026-98613 · Linux · Linux

CVE-2026-97949

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
configfs: unhash the dentry before dropping the item in rmdir
configfs get config item() treats a hashed dentry as proof that sd->s element is a live config item. configfs rmdir() breaks that: simple rmdir() leaves the dentry hashed, the last reference to the item is dropped right after, and the dentry is only unhashed by d delete() once ->rmdir() has returned. configfs symlink() resolves its target holding no lock on it, so get target() can land in that window:
BUG: KASAN: slab-use-after-free in config item get+0x26/0x90 get target fs/configfs/symlink.c:128 [inline] configfs symlink+0x4ab/0x1030 fs/configfs/symlink.c:185
Unhash in configfs remove dir(), while the item is still guaranteed to be there. A reference obtained just before that stays harmless, as create link() rechecks CONFIGFS USET DROPPING, already set by configfs detach prep(). Both configfs unregister subsystem() paths d drop() after detaching, so this only makes rmdir match them.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97949

Affected Products

Linux