{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93810","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-18T17:59:28.790Z","datePublished":"2026-09-24T16:02:46.426Z","dateUpdated":"2026-10-03T10:57:42.502Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:57:42.502Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Fix double fput\n\nFix a double fput() in error handling in cachefiles_create_tmpfile()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The extra fput is in cachefiles_create_tmpfile(), reached from nfs_fscache_open_file() (or CIFS/9p/AFS/Ceph fscache_use_cookie()) → fscache_perform_lookup() → cachefiles_lookup_cookie() → cachefiles_look_up_object() → cachefiles_create_file(), or from cachefiles_invalidate_cookie(); a local open/inval of an fscache-backed file is the entry, not a remote protocol message.\nAC:H - The double fput runs only when kernel_tmpfile_open()'s file has a NULL f_op->read_iter or f_op->write_iter. cachefiles_add_cache() requires tmpfile/xattr/sync_fs and s_blocksize<=PAGE_SIZE but never checks those f_ops; the only in-tree tmpfile FS lacking write_iter is hugetlbfs, which add_cache rejects, so an attacker cannot make a bound ext4/xfs/btrfs/f2fs tmpfile take this branch.\nPR:L - nfs_fscache_open_file() and the sibling fscache_use_cookie() open paths have no capable() check, so an unprivileged user with read access on an already-bound cachefiles/fscache mount drives cookie lookup into cachefiles_create_tmpfile(); cachefiles_daemon_open() needs init-namespace CAP_SYS_ADMIN, but that is not this trigger.\nUI:N - The attacker themselves open or invalidate files on the fscache-enabled netfs mount, which queues fscache_perform_lookup() into cachefiles_create_tmpfile(); no other user must mount the volume or issue cachefilesd commands.\nS:U - Double-putting the cache tmpfile's struct file corrupts host kernel file-refcount and filp_cachep state only; it does not cross a KVM/Xen, IOMMU, or other distinct authority.\nC:H - On the !read_iter/!write_iter branch, cachefiles_create_tmpfile() fput()s then err_unuse calls file_inode(file) and fput()s again. fscache_perform_lookup() runs in a PF_KTHREAD worker so the first put is deferred via delayed_fput_work; a later file_inode() on that pointer is a UAF read of a SLAB_TYPESAFE_BY_RCU struct file.\nI:H - The leftover fput before goto err_unuse is a struct-file double-put: if delayed __fput() has already file_free()'d the tmpfile, the second file_ref_put() writes a recycled filp_cachep object (or an underflowed live ref into the dead zone), a UAF write primitive against struct file.\nA:H - The second put hits __file_ref_put_badval()'s \"imbalanced put on file reference count\" WARN_ONCE, and if delayed_fput already ran, file_inode()/inode_lock/fput in cachefiles_create_tmpfile() err_unuse dereference freed memory and oops the fscache worker."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/cachefiles/namei.c"],"versions":[{"version":"24a81759b65fa85767739999d91523691c5e2ea5","lessThan":"e582a3e99584d5a634a3cbce4b12e9381fd5d964","status":"affected","versionType":"git"},{"version":"24a81759b65fa85767739999d91523691c5e2ea5","lessThan":"246098a2b8e88761e92cf82c1be1ec576437b176","status":"affected","versionType":"git"},{"version":"24a81759b65fa85767739999d91523691c5e2ea5","lessThan":"e9c2e68c3890a935abbd5f54dbce653f9a16836c","status":"affected","versionType":"git"},{"version":"24a81759b65fa85767739999d91523691c5e2ea5","lessThan":"90b306eee037d0a6a8f4aac834b46e05c5ddd0bf","status":"affected","versionType":"git"},{"version":"24a81759b65fa85767739999d91523691c5e2ea5","lessThan":"af6830cc12dfe86c832dccc9c9878a93aaa22f83","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/cachefiles/namei.c"],"versions":[{"version":"6.1","status":"affected"},{"version":"0","lessThan":"6.1","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e582a3e99584d5a634a3cbce4b12e9381fd5d964"},{"url":"https://git.kernel.org/stable/c/246098a2b8e88761e92cf82c1be1ec576437b176"},{"url":"https://git.kernel.org/stable/c/e9c2e68c3890a935abbd5f54dbce653f9a16836c"},{"url":"https://git.kernel.org/stable/c/90b306eee037d0a6a8f4aac834b46e05c5ddd0bf"},{"url":"https://git.kernel.org/stable/c/af6830cc12dfe86c832dccc9c9878a93aaa22f83"}],"title":"cachefiles: Fix double fput","x_generator":{"engine":"bippy-1.2.0"}}}}