{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97938","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:18:58.204Z","datePublished":"2026-09-25T10:22:51.720Z","dateUpdated":"2026-10-03T11:00:48.282Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T11:00:48.282Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nreboot: fix cad_pid use-after-free race\n\ncad_pid is a single kernel-wide struct pid pointer. proc_do_cad_pid()\nreads it and passes it to pid_vnr() without protecting the lifetime of\nthe referenced struct pid. A concurrent writer can replace cad_pid and\ndrop the final reference to the old struct pid after the reader has\nloaded the pointer but before pid_vnr() has finished dereferencing it,\ncausing a use-after-free.\n\nkill_cad_pid() has the same lifetime race when it passes cad_pid to\nkill_pid().\n\nAt the time this issue was reported, an unprivileged user could reach the\nsysctl through user and PID namespaces because cad_pid was registered in\npid_table[]. Moving cad_pid back to the global reboot sysctl table\ncorrected that namespace and permission mismatch, but did not fix the\nunderlying lifetime race.\n\nFix this by treating cad_pid as an RCU-protected pointer at both read\nsites and by waiting for a grace period before dropping the old reference\non the write side.\n\ncall_rcu(&old_pid->rcu, ...) cannot be used here because free_pid()\nalso queues pid->rcu; queueing the same rcu_head twice can corrupt the\nRCU callback list.\n\nOriginal KASAN crash stack:\n  kernel/pid.c:545 pid_nr_ns()        # reads freed pid->level\n  kernel/pid.c:556 pid_vnr()          # calls pid_nr_ns()\n  kernel/pid.c:775 proc_do_cad_pid()  # calls pid_vnr(cad_pid)"}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/linux/sched.h","include/linux/sched/signal.h","init/main.c","kernel/reboot.c","kernel/signal.c"],"versions":[{"version":"9ec52099e4b8678a60e9f93e41ad87885d64f3e6","lessThan":"ae3e53fe3c1241855e3a88f74877738349948c78","status":"affected","versionType":"git"},{"version":"9ec52099e4b8678a60e9f93e41ad87885d64f3e6","lessThan":"ad72e2566643fff7f01666d845fb026898155e1f","status":"affected","versionType":"git"},{"version":"9ec52099e4b8678a60e9f93e41ad87885d64f3e6","lessThan":"9a17b0e053197a6a42cdc75e75a35b17aa662088","status":"affected","versionType":"git"},{"version":"9ec52099e4b8678a60e9f93e41ad87885d64f3e6","lessThan":"5a88f78df753993469dab4d1831f8fb4256a9468","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/linux/sched.h","include/linux/sched/signal.h","init/main.c","kernel/reboot.c","kernel/signal.c"],"versions":[{"version":"2.6.19","status":"affected"},{"version":"0","lessThan":"2.6.19","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.7","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc3","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"7.2.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.19","versionEndExcluding":"7.3-rc3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ae3e53fe3c1241855e3a88f74877738349948c78"},{"url":"https://git.kernel.org/stable/c/ad72e2566643fff7f01666d845fb026898155e1f"},{"url":"https://git.kernel.org/stable/c/9a17b0e053197a6a42cdc75e75a35b17aa662088"},{"url":"https://git.kernel.org/stable/c/5a88f78df753993469dab4d1831f8fb4256a9468"}],"title":"reboot: fix cad_pid use-after-free race","x_generator":{"engine":"bippy-1.2.0"}}}}