« Volver al listado

CVE-2026-74359

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

configfs_lookup(): don't leave ->s_dentry dangling on failure

Normally ->s_dentry is cleared when dentry it's pointing to becomes negative (on eviction, realistically). However, that only happens if dentry gets to be positive in the first place; in case of inode allocation failure dentry never becomes positive, so ->d_iput() is not called at all.

We do part of what normally would've been done by configfs_d_iput() (dropping the reference to configfs_dirent) manually, but we do not clear ->s_dentry there. Sloppy as it is, it does not matter in case of configfs_create_{dir,link}() - there configfs_dirent does not survive dropping the sole reference to it.

Leer descripción completaMostrar menos

However, for configfs_lookup() it *does* survive, with a dangling pointer to soon to be freed dentry sitting it its ->s_dentry.

Subsequent getdents(2) in that directory will end up dereferencing that pointer in order to pick the inode number. Use after free...

This is the minimal fix; the right approach is to set the linkage between dentry and configfs_dirent only after we know that we have an inode, but that takes more surgery and the bug had been there since 2006, so...

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local con PR:L que permite escalar privilegios vía use-after-free en configfs_lookup(). El defecto causa dereferencia de puntero dangling en getdents(2), permitiendo DoS o lectura de memoria del kernel.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74359",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3d0f89bb169482d26d5aa4e82e763077e7e9bc4d",
              "lessThan": "3e83b2203aa59bd279e4f677ec793d49dc9d019e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3d0f89bb169482d26d5aa4e82e763077e7e9bc4d",
              "lessThan": "b6e9c82522ddaa3ac0706b295ff4a71975d4f883",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3d0f89bb169482d26d5aa4e82e763077e7e9bc4d",
              "lessThan": "eee07d769da5ac4e4f7bd0bc17828646a318d499",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3d0f89bb169482d26d5aa4e82e763077e7e9bc4d",
              "lessThan": "9c747dcee164ead300de90550ad9e4122f0d1bbb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3d0f89bb169482d26d5aa4e82e763077e7e9bc4d",
              "lessThan": "c3b073a209a9baa691b744318ac929fecdd8847c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3d0f89bb169482d26d5aa4e82e763077e7e9bc4d",
              "lessThan": "57088b06109f3222963c639d8d743f42c2899b13",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3d0f89bb169482d26d5aa4e82e763077e7e9bc4d",
              "lessThan": "10da12d352b7b2bb330a8609fdda9a58bf0e9856",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/configfs/dir.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/configfs/dir.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:37.430",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/10da12d352b7b2bb330a8609fdda9a58bf0e9856",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3e83b2203aa59bd279e4f677ec793d49dc9d019e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/57088b06109f3222963c639d8d743f42c2899b13",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9c747dcee164ead300de90550ad9e4122f0d1bbb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b6e9c82522ddaa3ac0706b295ff4a71975d4f883",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c3b073a209a9baa691b744318ac929fecdd8847c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/eee07d769da5ac4e4f7bd0bc17828646a318d499",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nconfigfs_lookup(): don't leave ->s_dentry dangling on failure\n\nNormally ->s_dentry is cleared when dentry it's pointing to becomes\nnegative (on eviction, realistically).  However, that only happens\nif dentry gets to be positive in the first place; in case of inode\nallocation failure dentry never becomes positive, so ->d_iput()\nis not called at all.\n\nWe do part of what normally would've been done by configfs_d_iput()\n(dropping the reference to configfs_dirent) manually, but we do\nnot clear ->s_dentry there.  Sloppy as it is, it does not matter in\ncase of configfs_create_{dir,link}() - there configfs_dirent does\nnot survive dropping the sole reference to it.\n\nHowever, for configfs_lookup() it *does* survive, with a dangling\npointer to soon to be freed dentry sitting it its ->s_dentry.\n\nSubsequent getdents(2) in that directory will end up dereferencing\nthat pointer in order to pick the inode number.  Use after free...\n\nThis is the minimal fix; the right approach is to set the linkage\nbetween dentry and configfs_dirent only after we know that we have\nan inode, but that takes more surgery and the bug had been there\nsince 2006, so..."
    }
  ],
  "lastModified": "2026-08-17T06:19:30.627",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}