configfs: fix lockless traversals of ->s_children

Summary

CVECVE-2026-74330
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 06:22:33 UTC
Updated2026-08-15 06:22:33 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: configfs: fix lockless traversals of ->s_children Having the parent directory locked protects entries from removal by another thread, but it does *not* protect cursors from being moved around by lseek() - or freed, for that matter.

Risk And Classification

EPSS: 0.001760000 probability, percentile 0.074240000 (date 2026-08-15)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 6f61076406251626be39651d114fac412b1e0c39 77fd6f50f633a52c2db061e7d71d8cb486b0265e git Not specified
CNA Linux Linux affected 6f61076406251626be39651d114fac412b1e0c39 91f289728ec706b7ff1ca0ee845dd73ff2253488 git Not specified
CNA Linux Linux affected 6f61076406251626be39651d114fac412b1e0c39 b166ab78dc3f48e83d2c80bdfde4159b31fdc5fb git Not specified
CNA Linux Linux affected 6f61076406251626be39651d114fac412b1e0c39 9e57e2863872e82e7c7237bc32299f67ebebc543 git Not specified
CNA Linux Linux affected 6f61076406251626be39651d114fac412b1e0c39 459860529c109c5ce08b81c0776ca1200eaaeb4a git Not specified
CNA Linux Linux affected 6f61076406251626be39651d114fac412b1e0c39 637ef4961470e04455102b34ac484a34d8eca0a4 git Not specified
CNA Linux Linux affected 6f61076406251626be39651d114fac412b1e0c39 e6d93108e0a27d7e6f95c7e45017d14ba2900d32 git Not specified
CNA Linux Linux affected 6f61076406251626be39651d114fac412b1e0c39 9b9e8bb81c41fd27e7b57a1c936fde140548535f git Not specified
CNA Linux Linux affected 2.6.27 Not specified
CNA Linux Linux unaffected 2.6.27 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.97 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.40 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/9e57e2863872e82e7c7237bc32299f67ebebc543 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/637ef4961470e04455102b34ac484a34d8eca0a4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b166ab78dc3f48e83d2c80bdfde4159b31fdc5fb 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/9b9e8bb81c41fd27e7b57a1c936fde140548535f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/77fd6f50f633a52c2db061e7d71d8cb486b0265e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/459860529c109c5ce08b81c0776ca1200eaaeb4a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/91f289728ec706b7ff1ca0ee845dd73ff2253488 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e6d93108e0a27d7e6f95c7e45017d14ba2900d32 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report