PT-2026-98614 · Linux · Linux
CVE-2026-97950
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
configfs: pin the symlink target's dirent instead of chasing ->ci dentry
create link() reads the target's configfs dirent from
item->ci dentry->d fsdata, relying on the item reference taken by
get target(). That reference pins the item, not its dentry: the dentry is
pinned by DCACHE PERSISTENT, which configfs remove dir() releases via
simple rmdir() while the item is still alive. A symlink racing with rmdir
of its target can therefore find ->ci dentry freed and its dirent
released, triggering WARN ON(!atomic read(&sd->s count)) in configfs get().
Take the dirent in get target() as well, under ->d lock and atomically
with the item reference, and pass it down to create link(). A hashed
dentry has not been killed yet, so its ->d fsdata reference keeps the
dirent alive there.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux