Junglewise Threat Intelligence

CVE-2026-63795: Linux Kernel use-after-free in 9p client p9_client_walk

CVE-2026-63795 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's 9p network protocol implementation. This flaw could allow a local user to cause a system crash or instability by triggering an error during specific file system operations. This impact on system availability could disrupt operations and require a reboot to restore service.

Technical details

A use-after-free (UAF) vulnerability exists in net/9p/client.c within the Linux kernel. When p9_client_walk() is invoked with 'clone' set to false, the 'fid' variable aliases 'oldfid'. If a multi-component walk fails after a request is sent, the error path (clunk_fid) unconditionally calls p9_fid_put(fid), which incorrectly decrements the reference count of oldfid while the caller still maintains ownership. This can lead to a refcount underflow or a use-after-free when the caller later attempts to use or release the same fid. The issue is fixed by ensuring p9_fid_put is only called if fid does not alias oldfid.

Affected products

  • Linux Linux 6.0 to 6.1.177, 6.6.144, 6.12.95

Timeline

  • 2026-05-28: other: Vulnerability fixed in upstream commits
  • 2026-07-19: disclosed: CVE published

References