-

CVE-2026-97950

configfs: pin the symlink target's dirent instead of chasing ->ci_dentry

In the Linux kernel, the following vulnerability has been resolved:

configfs: pin the symlink target's dirent instead of chasing ->ci_dentry

create_link() reads the target's configfs_dirent from
item->ci_dentry->d_fsdata, relying on the item reference taken by
get_target().  That reference pins the item, not its dentry: the dentry is
pinned by DCACHE_PERSISTENT, which configfs_remove_dir() releases via
simple_rmdir() while the item is still alive.  A symlink racing with rmdir
of its target can therefore find ->ci_dentry freed and its dirent
released, triggering WARN_ON(!atomic_read(&sd->s_count)) in configfs_get().

Take the dirent in get_target() as well, under ->d_lock and atomically
with the item reference, and pass it down to create_link().  A hashed
dentry has not been killed yet, so its ->d_fsdata reference keeps the
dirent alive there.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 7063fbf2261194f72ee75afca67b3b38b554b5fa
Version < 846ff40fd57a47e59a41f4e331ec3b34efaddc23
Status affected
Version 7063fbf2261194f72ee75afca67b3b38b554b5fa
Version < 4f54beb2e7f6d399396466682fba3539bcdcb414
Status affected
Version 7063fbf2261194f72ee75afca67b3b38b554b5fa
Version < d47c5de1cd6bfbe1067fc310bf90e4e00205e839
Status affected
Version 7063fbf2261194f72ee75afca67b3b38b554b5fa
Version < a7c1290eef60711c10289c056ad32ed1f2b47b12
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.16
Status affected
Version 0
Version < 2.6.16
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.086
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4f54beb2e7f6d399396466682fba3539bcdcb414
https://git.kernel.org/stable/c/d47c5de1cd6bfbe1067fc310bf90e4e00205e839
https://git.kernel.org/stable/c/a7c1290eef60711c10289c056ad32ed1f2b47b12
https://git.kernel.org/stable/c/846ff40fd57a47e59a41f4e331ec3b34efaddc23