« Volver al listado

CVE-2026-74342

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

kernfs: link kn to its parent before the LSM init hook

After commit 12e9e3cd03b5 ("simpe_xattr: use per-sb cache"), kernfs_xattr_set() and kernfs_xattr_get() compute the cache via kernfs_root(kn) before any other check. kernfs_root(kn) walks kn->__parent first and falls back to kn->dir.root, both of which are NULL on a freshly kmem_cache_zalloc()'d kn. kn->__parent was being set in kernfs_new_node() after __kernfs_new_node() returned, and kn->dir.root is set even later by kernfs_create_dir_ns() / kernfs_create_empty_dir().

The LSM kernfs_init_security hook is invoked from inside __kernfs_new_node(), before either field has been initialized. selinux_kernfs_init_security() ends with kernfs_xattr_set(kn, XATTR_NAME_SELINUX, ...). kernfs_root(kn) then returns NULL, and &((struct kernfs_root *)NULL)->xa_cache evaluates to offsetof(struct kernfs_root, xa_cache) which faults:

Leer descripción completaMostrar menos

Reproduces deterministically at PID 1 (systemd) on an SELinux-enabled distro. The first cgroup mkdir under /sys/fs/cgroup with a labelled parent panics the kernel.

The LSM hook's contract is that the kn_dir argument is the parent of the new kn, so kn->__parent should already point at kn_dir when the hook runs. Move kernfs_get(parent) and rcu_assign_pointer of kn->__parent from kernfs_new_node() into __kernfs_new_node() right before the security hook, and unwind the parent reference on the err_out4 path. kernfs_root(kn) then takes its parent branch during the hook and returns parent->dir.root, which is the correct root.

This also closes the same-shape latent bug in kernfs_xattr_get() (which today is hidden only by kernfs_iattrs_noalloc() returning NULL on a fresh kn).

Detalles técnicos trazas, registros y código del informe original
  BUG: kernel NULL pointer dereference, address: 00000000000000e0
  RIP: 0010:simple_xattr_set+0x27/0x8b0
  Call Trace:
   kernfs_xattr_set+0x63/0xb0
   selinux_kernfs_init_security+0x13b/0x270
   security_kernfs_init_security+0x36/0xc0
   __kernfs_new_node+0x182/0x290
   kernfs_new_node+0x80/0xc0
   kernfs_create_dir_ns+0x2b/0xa0
   cgroup_create+0x116/0x380
   cgroup_mkdir+0x7c/0x1a0

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74342",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "319b82e8b46edaf557436ad858e734e583f78ec9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "6cccc49b027c7551ffc1d2532f2ef1922661f3da",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "7.1.5",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/kernfs/dir.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/kernfs/dir.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:35.253",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/319b82e8b46edaf557436ad858e734e583f78ec9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6cccc49b027c7551ffc1d2532f2ef1922661f3da",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nkernfs: link kn to its parent before the LSM init hook\n\nAfter commit 12e9e3cd03b5 (\"simpe_xattr: use per-sb cache\"),\nkernfs_xattr_set() and kernfs_xattr_get() compute the cache via\nkernfs_root(kn) before any other check.  kernfs_root(kn) walks\nkn->__parent first and falls back to kn->dir.root, both of which are\nNULL on a freshly kmem_cache_zalloc()'d kn. kn->__parent was being set\nin kernfs_new_node() after __kernfs_new_node() returned, and kn->dir.root\nis set even later by kernfs_create_dir_ns() / kernfs_create_empty_dir().\n\nThe LSM kernfs_init_security hook is invoked from inside\n__kernfs_new_node(), before either field has been initialized.\nselinux_kernfs_init_security() ends with kernfs_xattr_set(kn,\nXATTR_NAME_SELINUX, ...).  kernfs_root(kn) then returns NULL, and\n&((struct kernfs_root *)NULL)->xa_cache evaluates to\noffsetof(struct kernfs_root, xa_cache) which faults:\n\n  BUG: kernel NULL pointer dereference, address: 00000000000000e0\n  RIP: 0010:simple_xattr_set+0x27/0x8b0\n  Call Trace:\n   kernfs_xattr_set+0x63/0xb0\n   selinux_kernfs_init_security+0x13b/0x270\n   security_kernfs_init_security+0x36/0xc0\n   __kernfs_new_node+0x182/0x290\n   kernfs_new_node+0x80/0xc0\n   kernfs_create_dir_ns+0x2b/0xa0\n   cgroup_create+0x116/0x380\n   cgroup_mkdir+0x7c/0x1a0\n\nReproduces deterministically at PID 1 (systemd) on an SELinux-enabled\ndistro. The first cgroup mkdir under /sys/fs/cgroup with a labelled\nparent panics the kernel.\n\nThe LSM hook's contract is that the kn_dir argument is the parent of\nthe new kn, so kn->__parent should already point at kn_dir when the\nhook runs.  Move kernfs_get(parent) and rcu_assign_pointer of\nkn->__parent from kernfs_new_node() into __kernfs_new_node() right\nbefore the security hook, and unwind the parent reference on the\nerr_out4 path.  kernfs_root(kn) then takes its parent branch during\nthe hook and returns parent->dir.root, which is the correct root.\n\nThis also closes the same-shape latent bug in kernfs_xattr_get() (which\ntoday is hidden only by kernfs_iattrs_noalloc() returning NULL on a\nfresh kn)."
    }
  ],
  "lastModified": "2026-08-17T06:19:28.763",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}