CVE-2026-74359 (GCVE-0-2026-74359)
Vulnerability from cvelistv5
Published
2026-08-15 05:58
Modified
2026-08-17 05:46
Summary
In the Linux kernel, the following vulnerability has been resolved: configfs_lookup(): don't leave ->s_dentry dangling on failure Normally ->s_dentry is cleared when dentry it's pointing to becomes negative (on eviction, realistically). However, that only happens if dentry gets to be positive in the first place; in case of inode allocation failure dentry never becomes positive, so ->d_iput() is not called at all. We do part of what normally would've been done by configfs_d_iput() (dropping the reference to configfs_dirent) manually, but we do not clear ->s_dentry there. Sloppy as it is, it does not matter in case of configfs_create_{dir,link}() - there configfs_dirent does not survive dropping the sole reference to it. However, for configfs_lookup() it *does* survive, with a dangling pointer to soon to be freed dentry sitting it its ->s_dentry. Subsequent getdents(2) in that directory will end up dereferencing that pointer in order to pick the inode number. Use after free... This is the minimal fix; the right approach is to set the linkage between dentry and configfs_dirent only after we know that we have an inode, but that takes more surgery and the bug had been there since 2006, so...
Impacted products
Vendor Product Version
Linux Linux Version: 3d0f89bb169482d26d5aa4e82e763077e7e9bc4d
Version: 3d0f89bb169482d26d5aa4e82e763077e7e9bc4d
Version: 3d0f89bb169482d26d5aa4e82e763077e7e9bc4d
Version: 3d0f89bb169482d26d5aa4e82e763077e7e9bc4d
Version: 3d0f89bb169482d26d5aa4e82e763077e7e9bc4d
Version: 3d0f89bb169482d26d5aa4e82e763077e7e9bc4d
Version: 3d0f89bb169482d26d5aa4e82e763077e7e9bc4d
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/configfs/dir.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "3e83b2203aa59bd279e4f677ec793d49dc9d019e",
              "status": "affected",
              "version": "3d0f89bb169482d26d5aa4e82e763077e7e9bc4d",
              "versionType": "git"
            },
            {
              "lessThan": "b6e9c82522ddaa3ac0706b295ff4a71975d4f883",
              "status": "affected",
              "version": "3d0f89bb169482d26d5aa4e82e763077e7e9bc4d",
              "versionType": "git"
            },
            {
              "lessThan": "eee07d769da5ac4e4f7bd0bc17828646a318d499",
              "status": "affected",
              "version": "3d0f89bb169482d26d5aa4e82e763077e7e9bc4d",
              "versionType": "git"
            },
            {
              "lessThan": "9c747dcee164ead300de90550ad9e4122f0d1bbb",
              "status": "affected",
              "version": "3d0f89bb169482d26d5aa4e82e763077e7e9bc4d",
              "versionType": "git"
            },
            {
              "lessThan": "c3b073a209a9baa691b744318ac929fecdd8847c",
              "status": "affected",
              "version": "3d0f89bb169482d26d5aa4e82e763077e7e9bc4d",
              "versionType": "git"
            },
            {
              "lessThan": "57088b06109f3222963c639d8d743f42c2899b13",
              "status": "affected",
              "version": "3d0f89bb169482d26d5aa4e82e763077e7e9bc4d",
              "versionType": "git"
            },
            {
              "lessThan": "10da12d352b7b2bb330a8609fdda9a58bf0e9856",
              "status": "affected",
              "version": "3d0f89bb169482d26d5aa4e82e763077e7e9bc4d",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/configfs/dir.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.16"
            },
            {
              "lessThan": "2.6.16",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.212",
                  "versionStartIncluding": "2.6.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.178",
                  "versionStartIncluding": "2.6.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.145",
                  "versionStartIncluding": "2.6.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.97",
                  "versionStartIncluding": "2.6.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.40",
                  "versionStartIncluding": "2.6.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.5",
                  "versionStartIncluding": "2.6.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "2.6.16",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nconfigfs_lookup(): don\u0027t leave -\u003es_dentry dangling on failure\n\nNormally -\u003es_dentry is cleared when dentry it\u0027s pointing to becomes\nnegative (on eviction, realistically).  However, that only happens\nif dentry gets to be positive in the first place; in case of inode\nallocation failure dentry never becomes positive, so -\u003ed_iput()\nis not called at all.\n\nWe do part of what normally would\u0027ve been done by configfs_d_iput()\n(dropping the reference to configfs_dirent) manually, but we do\nnot clear -\u003es_dentry there.  Sloppy as it is, it does not matter in\ncase of configfs_create_{dir,link}() - there configfs_dirent does\nnot survive dropping the sole reference to it.\n\nHowever, for configfs_lookup() it *does* survive, with a dangling\npointer to soon to be freed dentry sitting it its -\u003es_dentry.\n\nSubsequent getdents(2) in that directory will end up dereferencing\nthat pointer in order to pick the inode number.  Use after free...\n\nThis is the minimal fix; the right approach is to set the linkage\nbetween dentry and configfs_dirent only after we know that we have\nan inode, but that takes more surgery and the bug had been there\nsince 2006, so..."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The bug is reached only via local VFS syscalls (openat/stat on a configfs attribute and getdents on its parent) against /sys/kernel/config; configfs is not exposed through network-facing kernel services such as ksmbd, nfsd, or the TCP/IP stack.\nAC:L - Exploitation is a deterministic error-path bug, not a race: inode allocation failure in configfs_lookup() leaves sd-\u003es_dentry dangling and a follow-up getdents reliably dereferences it; the attacker can force ENOMEM by applying memory pressure they control.\nPR:L - Default configfs modes (0755 directories, 0644 attributes) let any local user read/list kernel-registered subsystem trees (e.g. nvmet, usb_gadget) without init-namespace root; mkdir/write still need admin, but triggering lookup on existing unpinned attributes does not.\nUI:N - No victim interaction is required beyond the attacker issuing their own syscalls on configfs paths; configfs is mounted at boot under /sys/kernel/config and exploitation does not depend on another user mounting or opening files.\nS:U - The use-after-free corrupts kernel heap memory and enables local privilege escalation within the same kernel security domain; it does not cross VM, IOMMU, or sandbox boundaries.\nC:H - configfs_readdir() reads d_inode() through a dangling sd-\u003es_dentry after failed lookup, giving a slab use-after-free read primitive on freed dentry/inode memory that can disclose kernel data or pointers via heap reuse.\nI:H - Reclaimed dentry/inode slabs let an attacker shape freed-object contents and convert the dangling pointer into arbitrary kernel writes and control-flow hijack, consistent with standard UAF exploitation of VFS objects.\nA:H - Dereferencing the freed dentry during getdents causes kernel oops/panic (as described in the fix); the UAF is repeatable and can deny service even when full exploitation is not attempted."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-17T05:46:19.411Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3e83b2203aa59bd279e4f677ec793d49dc9d019e"
        },
        {
          "url": "https://git.kernel.org/stable/c/b6e9c82522ddaa3ac0706b295ff4a71975d4f883"
        },
        {
          "url": "https://git.kernel.org/stable/c/eee07d769da5ac4e4f7bd0bc17828646a318d499"
        },
        {
          "url": "https://git.kernel.org/stable/c/9c747dcee164ead300de90550ad9e4122f0d1bbb"
        },
        {
          "url": "https://git.kernel.org/stable/c/c3b073a209a9baa691b744318ac929fecdd8847c"
        },
        {
          "url": "https://git.kernel.org/stable/c/57088b06109f3222963c639d8d743f42c2899b13"
        },
        {
          "url": "https://git.kernel.org/stable/c/10da12d352b7b2bb330a8609fdda9a58bf0e9856"
        }
      ],
      "title": "configfs_lookup(): don\u0027t leave -\u003es_dentry dangling on failure",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-74359",
    "datePublished": "2026-08-15T05:58:43.456Z",
    "dateReserved": "2026-08-15T05:44:03.887Z",
    "dateUpdated": "2026-08-17T05:46:19.411Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…