7.8

CVE-2026-97594

landlock: Fix use-after-free of the source's parent directory

In the Linux kernel, the following vulnerability has been resolved:

landlock: Fix use-after-free of the source's parent directory

current_check_refer_path() reads old_dentry->d_parent without holding a
reference nor a lock on it, and then dereferences it in
collect_domain_accesses() and in the audit record.

A reference on a child does not pin its parent: __d_move() reassigns
dentry->d_parent and drops the reference the child held on its former
parent.  hook_path_rename() is not affected because the rename path
calls lock_rename() before the hook, so the source cannot be reparented
under it.  hook_path_link() has no such protection: filename_linkat()
holds a reference on the source dentry but neither locks nor references
its parent, so a concurrent rename(2) can reparent the source while
security_path_link() runs, and the former parent can then be removed and
freed while the hook walks it.

A process can trigger this after entering a Landlock domain that handles
at least one filesystem access right.  The process can then race a
linkat(2) loop against rename(2) and rmdir(2):

  BUG: KASAN: slab-use-after-free in collect_domain_accesses+0x278/0x290
  Read of size 4 at addr ffff888160bd53f4 by task llrepro2/549
   collect_domain_accesses+0x278/0x290
   current_check_refer_path+0x952/0x1120
   security_path_link+0x1be/0x320
   filename_linkat+0x342/0x6d0
   __x64_sys_linkat+0xfa/0x150
  Freed by task 562:
   kmem_cache_free+0x139/0x4c0
   i_callback+0x4b/0x80
   rcu_core+0x7dc/0x10a0

Take a reference on the dentry selected as the source parent, using
dget() for the common-mount-root case and dget_parent() otherwise.
Release it after the hierarchy walk and synchronous audit logging.

[mic: Clarify the caller, reachability, and reference handling]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b91c3e4ea756b12b7d992529226edce1cfd854d7
Version < 4c37992b9668c4f37aae41dd95c369f7b6009915
Status affected
Version b91c3e4ea756b12b7d992529226edce1cfd854d7
Version < 379efd2ce8b26fd35feb13ccc2f671ff105a5052
Status affected
Version b91c3e4ea756b12b7d992529226edce1cfd854d7
Version < ba29c46ccfe3ebadfb8aa18149186c49f84b14f8
Status affected
Version b91c3e4ea756b12b7d992529226edce1cfd854d7
Version < 2c6dc792538260a8087ac5b22c31b3b8e47c85d6
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.19
Status affected
Version 0
Version < 5.19
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.041
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/379efd2ce8b26fd35feb13ccc2f671ff105a5052
https://git.kernel.org/stable/c/ba29c46ccfe3ebadfb8aa18149186c49f84b14f8
https://git.kernel.org/stable/c/2c6dc792538260a8087ac5b22c31b3b8e47c85d6
https://git.kernel.org/stable/c/4c37992b9668c4f37aae41dd95c369f7b6009915