CVE-2026-97950
In the Linux kernel, the following vulnerability has been resolved: configfs: pin the symlink target's dirent instead of chasing ->ci_dentry create_link() reads the target's configfs_dirent from item->ci_dentry->d_fsdata, relying on the item reference taken by get_target(). That reference pins the item, not its dentry: the dentry is pinned by DCACHE_PERSISTENT, which configfs_remove_dir() releases via simple_rmdir() while the item is still alive. A symlink racing with rmdir of its target can therefore find ->ci_dentry freed and its dirent released, triggering WARN_ON(!atomic_read(&sd->s_count)) in configfs_get(). Take the dirent in get_target() as well, under ->d_lock and atomically with the item reference, and pass it down to create_link(). A hashed dentry has not been killed yet, so its ->d_fsdata reference keeps the dirent alive there.
Affected versions
Linux kernel versions
2.6.16
and later are affected. Fixed in
6.12.112,
6.18.53,
7.2.7,
7.3-rc3
and their respective stable series.
References
4 totalFrequently asked questions
-
What is CVE-2026-97950?
CVE-2026-97950 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 2.6.16 onward and has been patched in 6.12.112, 6.18.53, 7.2.7 and others. CVE-2026-97950 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-97950?
Yes. CVE-2026-97950 has been patched. Fixed versions include 6.12.112, 6.18.53, 7.2.7 and others. If you are running Linux kernel 2.6.16 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-97950 actively exploited?
No. CVE-2026-97950 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.