{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74359","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.887Z","datePublished":"2026-08-15T05:58:43.456Z","dateUpdated":"2026-08-17T05:46:19.411Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:46:19.411Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nconfigfs_lookup(): don't leave ->s_dentry dangling on failure\n\nNormally ->s_dentry is cleared when dentry it's pointing to becomes\nnegative (on eviction, realistically).  However, that only happens\nif dentry gets to be positive in the first place; in case of inode\nallocation failure dentry never becomes positive, so ->d_iput()\nis not called at all.\n\nWe do part of what normally would've been done by configfs_d_iput()\n(dropping the reference to configfs_dirent) manually, but we do\nnot clear ->s_dentry there.  Sloppy as it is, it does not matter in\ncase of configfs_create_{dir,link}() - there configfs_dirent does\nnot survive dropping the sole reference to it.\n\nHowever, for configfs_lookup() it *does* survive, with a dangling\npointer to soon to be freed dentry sitting it its ->s_dentry.\n\nSubsequent getdents(2) in that directory will end up dereferencing\nthat pointer in order to pick the inode number.  Use after free...\n\nThis is the minimal fix; the right approach is to set the linkage\nbetween dentry and configfs_dirent only after we know that we have\nan inode, but that takes more surgery and the bug had been there\nsince 2006, so..."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only via local VFS syscalls (openat/stat on a configfs attribute and getdents on its parent) against /sys/kernel/config; configfs is not exposed through network-facing kernel services such as ksmbd, nfsd, or the TCP/IP stack.\nAC:L - Exploitation is a deterministic error-path bug, not a race: inode allocation failure in configfs_lookup() leaves sd->s_dentry dangling and a follow-up getdents reliably dereferences it; the attacker can force ENOMEM by applying memory pressure they control.\nPR:L - Default configfs modes (0755 directories, 0644 attributes) let any local user read/list kernel-registered subsystem trees (e.g. nvmet, usb_gadget) without init-namespace root; mkdir/write still need admin, but triggering lookup on existing unpinned attributes does not.\nUI:N - No victim interaction is required beyond the attacker issuing their own syscalls on configfs paths; configfs is mounted at boot under /sys/kernel/config and exploitation does not depend on another user mounting or opening files.\nS:U - The use-after-free corrupts kernel heap memory and enables local privilege escalation within the same kernel security domain; it does not cross VM, IOMMU, or sandbox boundaries.\nC:H - configfs_readdir() reads d_inode() through a dangling sd->s_dentry after failed lookup, giving a slab use-after-free read primitive on freed dentry/inode memory that can disclose kernel data or pointers via heap reuse.\nI:H - Reclaimed dentry/inode slabs let an attacker shape freed-object contents and convert the dangling pointer into arbitrary kernel writes and control-flow hijack, consistent with standard UAF exploitation of VFS objects.\nA:H - Dereferencing the freed dentry during getdents causes kernel oops/panic (as described in the fix); the UAF is repeatable and can deny service even when full exploitation is not attempted."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/configfs/dir.c"],"versions":[{"version":"3d0f89bb169482d26d5aa4e82e763077e7e9bc4d","lessThan":"3e83b2203aa59bd279e4f677ec793d49dc9d019e","status":"affected","versionType":"git"},{"version":"3d0f89bb169482d26d5aa4e82e763077e7e9bc4d","lessThan":"b6e9c82522ddaa3ac0706b295ff4a71975d4f883","status":"affected","versionType":"git"},{"version":"3d0f89bb169482d26d5aa4e82e763077e7e9bc4d","lessThan":"eee07d769da5ac4e4f7bd0bc17828646a318d499","status":"affected","versionType":"git"},{"version":"3d0f89bb169482d26d5aa4e82e763077e7e9bc4d","lessThan":"9c747dcee164ead300de90550ad9e4122f0d1bbb","status":"affected","versionType":"git"},{"version":"3d0f89bb169482d26d5aa4e82e763077e7e9bc4d","lessThan":"c3b073a209a9baa691b744318ac929fecdd8847c","status":"affected","versionType":"git"},{"version":"3d0f89bb169482d26d5aa4e82e763077e7e9bc4d","lessThan":"57088b06109f3222963c639d8d743f42c2899b13","status":"affected","versionType":"git"},{"version":"3d0f89bb169482d26d5aa4e82e763077e7e9bc4d","lessThan":"10da12d352b7b2bb330a8609fdda9a58bf0e9856","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/configfs/dir.c"],"versions":[{"version":"2.6.16","status":"affected"},{"version":"0","lessThan":"2.6.16","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.16","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.16","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.16","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.16","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.16","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.16","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.16","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3e83b2203aa59bd279e4f677ec793d49dc9d019e"},{"url":"https://git.kernel.org/stable/c/b6e9c82522ddaa3ac0706b295ff4a71975d4f883"},{"url":"https://git.kernel.org/stable/c/eee07d769da5ac4e4f7bd0bc17828646a318d499"},{"url":"https://git.kernel.org/stable/c/9c747dcee164ead300de90550ad9e4122f0d1bbb"},{"url":"https://git.kernel.org/stable/c/c3b073a209a9baa691b744318ac929fecdd8847c"},{"url":"https://git.kernel.org/stable/c/57088b06109f3222963c639d8d743f42c2899b13"},{"url":"https://git.kernel.org/stable/c/10da12d352b7b2bb330a8609fdda9a58bf0e9856"}],"title":"configfs_lookup(): don't leave ->s_dentry dangling on failure","x_generator":{"engine":"bippy-1.2.0"}}}}