-

CVE-2026-97949

configfs: unhash the dentry before dropping the item in rmdir

In the Linux kernel, the following vulnerability has been resolved:

configfs: unhash the dentry before dropping the item in rmdir

configfs_get_config_item() treats a hashed dentry as proof that
sd->s_element is a live config_item.  configfs_rmdir() breaks that:
simple_rmdir() leaves the dentry hashed, the last reference to the item is
dropped right after, and the dentry is only unhashed by d_delete() once
->rmdir() has returned.  configfs_symlink() resolves its target holding no
lock on it, so get_target() can land in that window:

  BUG: KASAN: slab-use-after-free in config_item_get+0x26/0x90
   get_target fs/configfs/symlink.c:128 [inline]
   configfs_symlink+0x4ab/0x1030 fs/configfs/symlink.c:185

Unhash in configfs_remove_dir(), while the item is still guaranteed to be
there.  A reference obtained just before that stays harmless, as
create_link() rechecks CONFIGFS_USET_DROPPING, already set by
configfs_detach_prep().  Both configfs_unregister_subsystem() paths
d_drop() after detaching, so this only makes rmdir match them.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 7063fbf2261194f72ee75afca67b3b38b554b5fa
Version < 446720051d44eebaa81b33969173160057b73a33
Status affected
Version 7063fbf2261194f72ee75afca67b3b38b554b5fa
Version < 5d7cbfb65e47cc71d5d94d87d5d0d1679080f3eb
Status affected
Version 7063fbf2261194f72ee75afca67b3b38b554b5fa
Version < 925d8564f1b2d9b46c5ab63b9bc942cea006da9b
Status affected
Version 7063fbf2261194f72ee75afca67b3b38b554b5fa
Version < f06c2d26d1999d37e93299db0ecead04ca7d0b9f
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.16
Status affected
Version 0
Version < 2.6.16
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5d7cbfb65e47cc71d5d94d87d5d0d1679080f3eb
https://git.kernel.org/stable/c/925d8564f1b2d9b46c5ab63b9bc942cea006da9b
https://git.kernel.org/stable/c/f06c2d26d1999d37e93299db0ecead04ca7d0b9f
https://git.kernel.org/stable/c/446720051d44eebaa81b33969173160057b73a33