« Volver al listado

CVE-2026-97950

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

configfs: pin the symlink target's dirent instead of chasing ->ci_dentry

create_link() reads the target's configfs_dirent from item->ci_dentry->d_fsdata, relying on the item reference taken by get_target(). That reference pins the item, not its dentry: the dentry is pinned by DCACHE_PERSISTENT, which configfs_remove_dir() releases via simple_rmdir() while the item is still alive. A symlink racing with rmdir of its target can therefore find ->ci_dentry freed and its dirent released, triggering WARN_ON(!atomic_read(&sd->s_count)) in configfs_get().

Leer descripción completaMostrar menos

Take the dirent in get_target() as well, under ->d_lock and atomically with the item reference, and pass it down to create_link(). A hashed dentry has not been killed yet, so its ->d_fsdata reference keeps the dirent alive there.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97950",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7063fbf2261194f72ee75afca67b3b38b554b5fa",
              "lessThan": "846ff40fd57a47e59a41f4e331ec3b34efaddc23",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7063fbf2261194f72ee75afca67b3b38b554b5fa",
              "lessThan": "4f54beb2e7f6d399396466682fba3539bcdcb414",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7063fbf2261194f72ee75afca67b3b38b554b5fa",
              "lessThan": "d47c5de1cd6bfbe1067fc310bf90e4e00205e839",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7063fbf2261194f72ee75afca67b3b38b554b5fa",
              "lessThan": "a7c1290eef60711c10289c056ad32ed1f2b47b12",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/configfs/symlink.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/configfs/symlink.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:22.567",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/4f54beb2e7f6d399396466682fba3539bcdcb414",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/846ff40fd57a47e59a41f4e331ec3b34efaddc23",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a7c1290eef60711c10289c056ad32ed1f2b47b12",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d47c5de1cd6bfbe1067fc310bf90e4e00205e839",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nconfigfs: pin the symlink target's dirent instead of chasing ->ci_dentry\n\ncreate_link() reads the target's configfs_dirent from\nitem->ci_dentry->d_fsdata, relying on the item reference taken by\nget_target().  That reference pins the item, not its dentry: the dentry is\npinned by DCACHE_PERSISTENT, which configfs_remove_dir() releases via\nsimple_rmdir() while the item is still alive.  A symlink racing with rmdir\nof its target can therefore find ->ci_dentry freed and its dirent\nreleased, triggering WARN_ON(!atomic_read(&sd->s_count)) in configfs_get().\n\nTake the dirent in get_target() as well, under ->d_lock and atomically\nwith the item reference, and pass it down to create_link().  A hashed\ndentry has not been killed yet, so its ->d_fsdata reference keeps the\ndirent alive there."
    }
  ],
  "lastModified": "2026-10-03T11:18:20.213",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}