PT-2026-98614 · Linux · Linux

CVE-2026-97950

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
configfs: pin the symlink target's dirent instead of chasing ->ci dentry
create link() reads the target's configfs dirent from item->ci dentry->d fsdata, relying on the item reference taken by get target(). That reference pins the item, not its dentry: the dentry is pinned by DCACHE PERSISTENT, which configfs remove dir() releases via simple rmdir() while the item is still alive. A symlink racing with rmdir of its target can therefore find ->ci dentry freed and its dirent released, triggering WARN ON(!atomic read(&sd->s count)) in configfs get().
Take the dirent in get target() as well, under ->d lock and atomically with the item reference, and pass it down to create link(). A hashed dentry has not been killed yet, so its ->d fsdata reference keeps the dirent alive there.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97950

Affected Products

Linux