PT-2026-98613 · Linux · Linux
CVE-2026-97949
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
configfs: unhash the dentry before dropping the item in rmdir
configfs get config item() treats a hashed dentry as proof that
sd->s element is a live config item. configfs rmdir() breaks that:
simple rmdir() leaves the dentry hashed, the last reference to the item is
dropped right after, and the dentry is only unhashed by d delete() once
->rmdir() has returned. configfs symlink() resolves its target holding no
lock on it, so get target() can land in that window:
BUG: KASAN: slab-use-after-free in config item get+0x26/0x90
get target fs/configfs/symlink.c:128 [inline]
configfs symlink+0x4ab/0x1030 fs/configfs/symlink.c:185
Unhash in configfs remove dir(), while the item is still guaranteed to be
there. A reference obtained just before that stays harmless, as
create link() rechecks CONFIGFS USET DROPPING, already set by
configfs detach prep(). Both configfs unregister subsystem() paths
d drop() after detaching, so this only makes rmdir match them.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux