CVE-2026-97410

In the Linux kernel, the following vulnerability has been resolved: netconsole: take target_cleanup_list_lock in drop_netconsole_target() drop_netconsole_target() unlinks the target while only holding target_list_lock. However, when the underlying interface has been unregistered, netconsole_netdev_event() moves the target from target_list to target_cleanup_list, and netconsole_process_cleanups_core() walks that list under target_cleanup_list_lock only. If a user removes the configfs target at the same time the cleanup worker is iterating target_cleanup_list, list_del() can corrupt the list because the two paths take disjoint locks while operating on the same list node. Acquire target_cleanup_list_lock around the list_del() so the unlink is serialised against netconsole_process_cleanups_core() regardless of which list the target currently belongs to. The state transition that downgrades STATE_DEACTIVATED to STATE_DISABLED is left intact and is performed under the same combined locking, preserving the existing ordering with resume_target().

Package Linux Kernel
Published 2026-09-24
Last modified 2026-09-25
Patch available
Yes

Affected versions

Linux kernel versions 6.12 and later are affected. Fixed in 6.12.111, 6.18.53, 7.2 and their respective stable series.

Affected from
≥ 6.12
Fixed in
✓ 6.12.111 6.12.x ✓ 6.18.53 6.18.x ✓ 7.2

Frequently asked questions

  • What is CVE-2026-97410?

    CVE-2026-97410 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.12 onward and has been patched in 6.12.111, 6.18.53 and 7.2. CVE-2026-97410 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-97410?

    Yes. CVE-2026-97410 has been patched. Fixed versions include 6.12.111, 6.18.53 and 7.2. If you are running Linux kernel 6.12 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-97410 actively exploited?

    No. CVE-2026-97410 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.