« Volver al listado

CVE-2026-74348

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ocfs2/dlm: require a ref for locking_state debugfs open

debug_lockres_open() copies inode->i_private into struct debug_lockres and debug_lockres_release() later drops that pointer with dlm_put(). That only works if open successfully pins the struct dlm_ctxt.

Today open calls dlm_grab(dlm) but ignores its return value. Once the last domain unregister has removed the context from dlm_domains, dlm_grab() returns NULL, yet open still stores the raw pointer and returns success. The later release path is outside the debugfs removal barrier, so it can call dlm_put() after dlm_free_ctxt_mem() has freed the context. KASAN reports this as a slab-use-after-free in dlm_put() called from debug_lockres_release().

Leer descripción completaMostrar menos

Fail the open when dlm_grab() cannot acquire the reference and unwind the seq_file private state before returning. That keeps locking_state from handing out a file descriptor whose release path does not own the dlm_ctxt.

The buggy scenario involves two paths, with each column showing the order within that path:

Detalles técnicos trazas, registros y código del informe original
locking_state debugfs open:          last domain unregister:
1. debug_lockres_open() reads        1. dlm_unregister_domain() calls
   inode->i_private.                    dlm_complete_dlm_shutdown().
2. debug_lockres_open() calls        2. shutdown removes the dlm_ctxt from
   dlm_grab(dlm) and gets NULL.         dlm_domains.
3. open still stores the raw dlm     3. final teardown reaches
   pointer in dl->dl_ctxt and           dlm_free_ctxt_mem() and frees it.
   returns success.
4. debug_lockres_release() later
   calls dlm_put(dl->dl_ctxt).

Validation reproduced this kernel report:
KASAN slab-use-after-free in dlm_put+0x82/0x200
RIP: 0033:0x7f4d349bc9e0
The buggy address belongs to the object at ffff888103a3c000 which belongs
to the cache kmalloc-2k of size 2048
The buggy address is located 816 bytes inside of freed 2048-byte region
[ffff888103a3c000, ffff888103a3c800)
Write of size 4
Call trace:
  dump_stack_lvl+0x66/0xa0 (?:?)
  print_report+0xd0/0x630 (?:?)
  dlm_put+0x82/0x200 (?:?)
  srso_alias_return_thunk+0x5/0xfbef5 (?:?)
  __virt_addr_valid+0x188/0x2f0 (?:?)
  kasan_report+0xe4/0x120 (?:?)
  kasan_check_range+0x105/0x1b0 (?:?)
  debug_lockres_release+0x53/0x80 (fs/ocfs2/dlm/dlmdebug.c:587)
  dlm_put+0x9/0x200 (?:?)
  debug_lockres_release+0x5c/0x80 (fs/ocfs2/dlm/dlmdebug.c:587)
  full_proxy_release+0x67/0x90 (?:?)
  __fput+0x1df/0x4b0 (?:?)
  do_raw_spin_lock+0x10f/0x1b0 (?:?)
  fput_close_sync+0xd2/0x170 (?:?)
  __x64_sys_close+0x55/0x90 (?:?)
  do_syscall_64+0x10c/0x640 (arch/x86/entry/syscall_64.c:87)
  irqentry_exit+0xac/0x6e0 (?:?)
  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)
Freed by task stack:
  kasan_save_stack+0x33/0x60 (?:?)
  kasan_save_track+0x14/0x30 (?:?)
  kasan_save_free_info+0x3b/0x60 (?:?)
  __kasan_slab_free+0x5f/0x80 (?:?)
  kfree+0x30f/0x580 (?:?)
  dlm_put+0x1ce/0x200 (?:?)
  dlm_unregister_domain+0xf6/0xb30 (?:?)
  o2cb_cluster_disconnect+0x6b/0x90 (?:?)
  ocfs2_cluster_disconnect+0x41/0x70 (?:?)
  ocfs2_dlm_shutdown+0x1c4/0x220 (?:?)
  ocfs2_dismount_volume+0x38a/0x550 (?:?)
  generic_shutdown_super+0xc3/0x220 (?:?)
  kill_block_super+0x29/0x60 (?:?)
  deactivate_locked_super+0x66/0xe0 (?:?)
  cleanup_mnt+0x13d/0x210 (?:?)
  task_work_run+0xfa/0x170 (?:?)
  exit_to_user_mode_loop+0xd6/0x430 (?:?)
  do_syscall_64+0x3cb/0x640 (arch/x86/entry/syscall_64.c:87)
  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74348",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4e3d24ed1a1285fe3289653aacc965642706bacb",
              "lessThan": "6cc93dea4078cbcddee63fa2234e382a76600464",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4e3d24ed1a1285fe3289653aacc965642706bacb",
              "lessThan": "90a6512425414098a63fc97b77bed089c75d106b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4e3d24ed1a1285fe3289653aacc965642706bacb",
              "lessThan": "5bee5d5f67aedd26d2b72e00e49dd93331fbcc30",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4e3d24ed1a1285fe3289653aacc965642706bacb",
              "lessThan": "aa7883b6a3c76301a3299deb34de948e73bb6a08",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4e3d24ed1a1285fe3289653aacc965642706bacb",
              "lessThan": "9c81c1a61a52b6ecf0d14f1dbd95f154a7a9e92a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4e3d24ed1a1285fe3289653aacc965642706bacb",
              "lessThan": "a087b2d3411e7f9df71ba3293596923ee2c70d65",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4e3d24ed1a1285fe3289653aacc965642706bacb",
              "lessThan": "a09831214912a1f270663d935613910fafd8d883",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4e3d24ed1a1285fe3289653aacc965642706bacb",
              "lessThan": "03ad858ce8064861ea580021976dc19b7aabb549",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/ocfs2/dlm/dlmdebug.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.26"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.26",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/ocfs2/dlm/dlmdebug.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:35.970",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/03ad858ce8064861ea580021976dc19b7aabb549",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5bee5d5f67aedd26d2b72e00e49dd93331fbcc30",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6cc93dea4078cbcddee63fa2234e382a76600464",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/90a6512425414098a63fc97b77bed089c75d106b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9c81c1a61a52b6ecf0d14f1dbd95f154a7a9e92a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a087b2d3411e7f9df71ba3293596923ee2c70d65",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a09831214912a1f270663d935613910fafd8d883",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aa7883b6a3c76301a3299deb34de948e73bb6a08",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2/dlm: require a ref for locking_state debugfs open\n\ndebug_lockres_open() copies inode->i_private into struct debug_lockres and\ndebug_lockres_release() later drops that pointer with dlm_put().  That\nonly works if open successfully pins the struct dlm_ctxt.\n\nToday open calls dlm_grab(dlm) but ignores its return value.  Once the\nlast domain unregister has removed the context from dlm_domains,\ndlm_grab() returns NULL, yet open still stores the raw pointer and returns\nsuccess.  The later release path is outside the debugfs removal barrier,\nso it can call dlm_put() after dlm_free_ctxt_mem() has freed the context. \nKASAN reports this as a slab-use-after-free in dlm_put() called from\ndebug_lockres_release().\n\nFail the open when dlm_grab() cannot acquire the reference and unwind the\nseq_file private state before returning.  That keeps locking_state from\nhanding out a file descriptor whose release path does not own the\ndlm_ctxt.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nlocking_state debugfs open:          last domain unregister:\n1. debug_lockres_open() reads        1. dlm_unregister_domain() calls\n   inode->i_private.                    dlm_complete_dlm_shutdown().\n2. debug_lockres_open() calls        2. shutdown removes the dlm_ctxt from\n   dlm_grab(dlm) and gets NULL.         dlm_domains.\n3. open still stores the raw dlm     3. final teardown reaches\n   pointer in dl->dl_ctxt and           dlm_free_ctxt_mem() and frees it.\n   returns success.\n4. debug_lockres_release() later\n   calls dlm_put(dl->dl_ctxt).\n\nValidation reproduced this kernel report:\nKASAN slab-use-after-free in dlm_put+0x82/0x200\nRIP: 0033:0x7f4d349bc9e0\nThe buggy address belongs to the object at ffff888103a3c000 which belongs\nto the cache kmalloc-2k of size 2048\nThe buggy address is located 816 bytes inside of freed 2048-byte region\n[ffff888103a3c000, ffff888103a3c800)\nWrite of size 4\nCall trace:\n  dump_stack_lvl+0x66/0xa0 (?:?)\n  print_report+0xd0/0x630 (?:?)\n  dlm_put+0x82/0x200 (?:?)\n  srso_alias_return_thunk+0x5/0xfbef5 (?:?)\n  __virt_addr_valid+0x188/0x2f0 (?:?)\n  kasan_report+0xe4/0x120 (?:?)\n  kasan_check_range+0x105/0x1b0 (?:?)\n  debug_lockres_release+0x53/0x80 (fs/ocfs2/dlm/dlmdebug.c:587)\n  dlm_put+0x9/0x200 (?:?)\n  debug_lockres_release+0x5c/0x80 (fs/ocfs2/dlm/dlmdebug.c:587)\n  full_proxy_release+0x67/0x90 (?:?)\n  __fput+0x1df/0x4b0 (?:?)\n  do_raw_spin_lock+0x10f/0x1b0 (?:?)\n  fput_close_sync+0xd2/0x170 (?:?)\n  __x64_sys_close+0x55/0x90 (?:?)\n  do_syscall_64+0x10c/0x640 (arch/x86/entry/syscall_64.c:87)\n  irqentry_exit+0xac/0x6e0 (?:?)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)\nFreed by task stack:\n  kasan_save_stack+0x33/0x60 (?:?)\n  kasan_save_track+0x14/0x30 (?:?)\n  kasan_save_free_info+0x3b/0x60 (?:?)\n  __kasan_slab_free+0x5f/0x80 (?:?)\n  kfree+0x30f/0x580 (?:?)\n  dlm_put+0x1ce/0x200 (?:?)\n  dlm_unregister_domain+0xf6/0xb30 (?:?)\n  o2cb_cluster_disconnect+0x6b/0x90 (?:?)\n  ocfs2_cluster_disconnect+0x41/0x70 (?:?)\n  ocfs2_dlm_shutdown+0x1c4/0x220 (?:?)\n  ocfs2_dismount_volume+0x38a/0x550 (?:?)\n  generic_shutdown_super+0xc3/0x220 (?:?)\n  kill_block_super+0x29/0x60 (?:?)\n  deactivate_locked_super+0x66/0xe0 (?:?)\n  cleanup_mnt+0x13d/0x210 (?:?)\n  task_work_run+0xfa/0x170 (?:?)\n  exit_to_user_mode_loop+0xd6/0x430 (?:?)\n  do_syscall_64+0x3cb/0x640 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)"
    }
  ],
  "lastModified": "2026-08-17T06:19:29.400",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}