Executive brief
A vulnerability in the Linux kernel's file system management could allow a local user to cause a system crash or instability. The issue occurs when the system incorrectly handles the unmounting of storage volumes, leading to internal reference counting errors. This could result in a denial-of-service condition, affecting the availability of the system.
Technical details
A race condition exists in the __legitimize_mnt() function within fs/namespace.c of the Linux kernel. The root cause is that the check for the MNT_SYNC_UMOUNT flag was performed outside of the mount_lock, allowing a race where a mount reference count (mnt_count) could be incremented after umount(2) verified the mount was not busy but before the flag was set. This leads to a leaked reference that eventually triggers a full mntput() in an unsafe context. An attacker with local access could potentially exploit this to cause a kernel panic or denial-of-service. The fix moves the MNT_SYNC_UMOUNT check under the protection of the mount_lock.
Affected products
- Linux Linux Kernel up to 5.4.294, 5.5 to 5.10.238, 5.11 to 5.15.185, 5.16 to 6.1.141, 6.2 to 6.6.93, 6.7 to 6.12.31, 6.13 to 6.14.9
Timeline
- 2025-06-18: disclosed
- 2025-06-18: advisory
References
- https://git.kernel.org/stable/c/250cf3693060a5f803c5f1ddc082bb06b16112a9
- https://git.kernel.org/stable/c/628fb00195ce21a90cf9e4e3d105cd9e58f77b40
- https://git.kernel.org/stable/c/8cafd7266fa02e0863bacbf872fe635c0b9725eb
- https://git.kernel.org/stable/c/9b0915e72b3cf52474dcee0b24a2f99d93e604a3
- https://git.kernel.org/stable/c/b55996939c71a3e1a38f3cdc6a8859797efc9083
- https://git.kernel.org/stable/c/b89eb56a378b7b2c1176787fc228d0a57172bdd5
- https://git.kernel.org/stable/c/d8ece4ced3b051e656c77180df2e69e19e24edc1