Executive brief
A vulnerability was identified in the Linux kernel's 9p network protocol implementation. This flaw could allow a local user to cause a system crash or instability by triggering an error during specific file system operations. This impact on system availability could disrupt operations and require a reboot to restore service.
Technical details
A use-after-free (UAF) vulnerability exists in net/9p/client.c within the Linux kernel. When p9_client_walk() is invoked with 'clone' set to false, the 'fid' variable aliases 'oldfid'. If a multi-component walk fails after a request is sent, the error path (clunk_fid) unconditionally calls p9_fid_put(fid), which incorrectly decrements the reference count of oldfid while the caller still maintains ownership. This can lead to a refcount underflow or a use-after-free when the caller later attempts to use or release the same fid. The issue is fixed by ensuring p9_fid_put is only called if fid does not alias oldfid.
Affected products
- Linux Linux 6.0 to 6.1.177, 6.6.144, 6.12.95
Timeline
- 2026-05-28: other: Vulnerability fixed in upstream commits
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/1a3860d46e3eb47dbd60339783cdad7904486b9f
- https://git.kernel.org/stable/c/6dbe9443d9f5f7fb6d319a7b77108853ae6c6bea
- https://git.kernel.org/stable/c/99c379ca1e221c3d75c7c804ebbf4e5ee37a3070
- https://git.kernel.org/stable/c/a61bdcba4f64c2f90d01461913f429ab151f1ca6
- https://git.kernel.org/stable/c/a7656d368265d085ac9bb85ab31b0cdb72ad8c38
- https://git.kernel.org/stable/c/b84f46179c806450b89821221ea5bd9a1698aba8