-
CVE-2026-97927
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:22:44
- Zuletzt bearbeitet 03.10.2026 11:18:10
- Erkennungen
ufs: create the root dentry after loading cylinder metadata
In the Linux kernel, the following vulnerability has been resolved: ufs: create the root dentry after loading cylinder metadata ufs_fill_super() installed sb->s_root before it loaded the cylinder group structures for a writable mount: sb->s_root = d_make_root(inode); ... if (!sb_rdonly(sb)) if (!ufs_read_cylinder_structures(sb)) goto failed; When ufs_read_cylinder_structures() failed, the error path freed the in-core superblock information and set sb->s_fs_info to NULL while sb->s_root stayed installed. get_tree_bdev() then reached deactivate_locked_super(), and because s_root was present, generic_shutdown_super() called sync_filesystem() and the put_super operation. Both dereference UFS_SB(sb), which is now NULL, so a mount that fails only while reading the cylinder groups oopses during teardown. A crafted image whose first cylinder group cannot be read reaches this path. Load the cylinder group metadata first and create the root dentry last, so the superblock is published to the VFS only once it is fully set up. ufs_setup_cstotal() and ufs_read_cylinder_structures() take only the super_block and do not use the root inode, so the reordering is safe.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
e58db6c2dce6e453dca26c3a4953002425201880
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
05360c6eb8388bb5adac3c439ffb1512de39550a
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
5cc48633fb76196b596a449ba1f4f642ad6125ce
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
cd21f1ff74b1c15077fa3b98e80da3b41055aae4
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
a9804121d55aaa4319c1cac00b99794aa177dd6a
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
785e523b6c1931d802cab9f85912f3e6c7028af1
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
8173e051a8acbb4ae6547be0436727944119e0b5
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
55a4c98abb9694b067c6a031d11501f06b6b523c
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.12
Status
affected
Version
0
Version <
2.6.12
Status
unaffected
Version <=
5.10.*
Version
5.10.271
Status
unaffected
Version <=
5.15.*
Version
5.15.222
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.088 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/a9804121d55aaa4319c1cac00b99794aa177dd6a
https://git.kernel.org/stable/c/785e523b6c1931d802cab9f85912f3e6c7028af1
https://git.kernel.org/stable/c/8173e051a8acbb4ae6547be0436727944119e0b5
https://git.kernel.org/stable/c/55a4c98abb9694b067c6a031d11501f06b6b523c
https://git.kernel.org/stable/c/05360c6eb8388bb5adac3c439ffb1512de39550a
https://git.kernel.org/stable/c/5cc48633fb76196b596a449ba1f4f642ad6125ce
https://git.kernel.org/stable/c/cd21f1ff74b1c15077fa3b98e80da3b41055aae4
https://git.kernel.org/stable/c/e58db6c2dce6e453dca26c3a4953002425201880