Junglewise Threat Intelligence

CVE-2026-74359: Linux kernel configfs use-after-free in directory lookup

CVE-2026-74359 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's configfs filesystem contains a use-after-free vulnerability in directory lookup operations. When inode allocation fails during a directory lookup, a dangling pointer is left in memory. Subsequent directory operations can trigger a crash or potentially allow arbitrary code execution by dereferencing this freed memory, affecting systems that rely on the configfs filesystem for hardware hotplug management or other configuration tasks.

Technical details

The vulnerability is a use-after-free in the configfs_lookup() function within fs/configfs/dir.c. When inode allocation fails, the function incorrectly leaves a dangling pointer (->s_dentry) in the configfs_dirent structure pointing to a freed dentry. This occurs because the dentry never becomes positive (since inode creation failed), so the normal cleanup callback (configfs_d_iput) is never invoked. Subsequent getdents(2) syscalls operating on the directory attempt to dereference this dangling pointer to obtain inode numbers, causing a use-after-free condition. Local users with access to configfs directories can trigger this via directory enumeration operations. The fix adds explicit null pointer assignment under spinlock when inode creation fails, clearing the stale reference before dentry freeing occurs. Patches are available in the stable Linux kernel git repository.

Affected products

  • Linux Linux kernel 2.6.16-rc3 and later (bug present since 2006)

Timeline

  • 2026-08-15: disclosed: CVE-2026-74359 published
  • 2026-05-12: patched: Fix committed upstream by Al Viro
  • 2026-07-24: patched: Fix backported to stable kernels

References

Related threats