Executive brief
A vulnerability in the Linux kernel's cachefiles system could cause improper error handling when creating directories. This component is responsible for caching data from network filesystems to local storage to improve performance. If an error occurs during directory creation, the system may fail to report it correctly, potentially leading to unpredictable system behavior or stability issues.
Technical details
A vulnerability exists in the Linux kernel's cachefiles subsystem within 'fs/cachefiles/namei.c'. When the 'vfs_mkdir()' function fails, the code fails to extract the error code from the returned error pointer. This results in the 'mkdir_error' label being reached with a return value of 0, causing the function to return 'ERR_PTR(0)' (NULL) instead of a valid error pointer. This improper error handling can lead to subsequent kernel instability or crashes (oops) if the calling function expects a valid error pointer or a successful object. The issue has been patched by ensuring 'PTR_ERR()' is called to capture the actual error code when 'vfs_mkdir()' fails.
Affected products
- Linux Linux Kernel 6.15, 7.0.11, 7.1
Timeline
- 2026-05-13: other: Patch submitted by author
- 2026-07-19: advisory: CVE published to NVD