PT-2026-98635 · Linux · Linux
CVE-2026-97971
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
nstree: check listing permission before taking a namespace reference
legitimize ns() takes a reference on the candidate namespace before
may list ns() has decided whether the caller may see it. The
free(ns put) cleanup on the denied path can drop the last reference to a
mount namespace while we still hold the rcu read lock, and put mnt ns()
may sleep there. This is the same problem commit 2ec2aff3c8e2 ("ns: make
sure reference are dropped outside of rcu lock") fixed for the put user()
path. Neither ns requested() nor may list ns() needs a reference, both
only look at the namespace type and at the caller's own namespaces, so do
the checks first and take the reference last.
Splat:
Voluntary context switch within RCU read-side critical section!
WARNING: kernel/rcu/tree plugin.h:332 at rcu note context switch+0x238/0x2a0, CPU#5: a/3442
CPU: 5 UID: 1000 PID: 3442 Comm: a Not tainted 7.0.0-30-generic #30-Ubuntu PREEMPT(lazy)
RIP: 0010:rcu note context switch+0x238/0x2a0
Call Trace:
schedule+0xcf/0x650
schedule+0x27/0x90
schedule preempt disabled+0x15/0x30
mutex lock.constprop.0+0x550/0xaf0
mutex lock slowpath+0x13/0x20
mutex lock+0x3b/0x50
exp funnel lock+0xb2/0x260
synchronize rcu expedited+0xe7/0x220
namespace unlock+0x26a/0x320
put mnt ns+0xd3/0x120
mntns put+0xe/0x20
do listns+0x13e/0x560
do sys listns+0x126/0x2d0
x64 sys listns+0x20/0x30
x64 sys call+0x2366/0x2390
do syscall 64+0x105/0x5a0
entry SYSCALL 64 after hwframe+0x76/0x7e
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux