{"api_version":"1","generated_at":"2026-10-01T19:08:53+00:00","cve":"CVE-2026-97938","urls":{"html":"https://cve.report/CVE-2026-97938","api":"https://cve.report/api/cve/CVE-2026-97938.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-97938","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-97938"},"summary":{"title":"reboot: fix cad_pid use-after-free race","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nreboot: fix cad_pid use-after-free race\n\ncad_pid is a single kernel-wide struct pid pointer. proc_do_cad_pid()\nreads it and passes it to pid_vnr() without protecting the lifetime of\nthe referenced struct pid. A concurrent writer can replace cad_pid and\ndrop the final reference to the old struct pid after the reader has\nloaded the pointer but before pid_vnr() has finished dereferencing it,\ncausing a use-after-free.\n\nkill_cad_pid() has the same lifetime race when it passes cad_pid to\nkill_pid().\n\nAt the time this issue was reported, an unprivileged user could reach the\nsysctl through user and PID namespaces because cad_pid was registered in\npid_table[]. Moving cad_pid back to the global reboot sysctl table\ncorrected that namespace and permission mismatch, but did not fix the\nunderlying lifetime race.\n\nFix this by treating cad_pid as an RCU-protected pointer at both read\nsites and by waiting for a grace period before dropping the old reference\non the write side.\n\ncall_rcu(&old_pid->rcu, ...) cannot be used here because free_pid()\nalso queues pid->rcu; queueing the same rcu_head twice can corrupt the\nRCU callback list.\n\nOriginal KASAN crash stack:\n  kernel/pid.c:545 pid_nr_ns()        # reads freed pid->level\n  kernel/pid.c:556 pid_vnr()          # calls pid_nr_ns()\n  kernel/pid.c:775 proc_do_cad_pid()  # calls pid_vnr(cad_pid)","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-25 11:17:21","updated_at":"2026-09-25 11:17:21"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/9a17b0e053197a6a42cdc75e75a35b17aa662088","name":"https://git.kernel.org/stable/c/9a17b0e053197a6a42cdc75e75a35b17aa662088","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5a88f78df753993469dab4d1831f8fb4256a9468","name":"https://git.kernel.org/stable/c/5a88f78df753993469dab4d1831f8fb4256a9468","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ad72e2566643fff7f01666d845fb026898155e1f","name":"https://git.kernel.org/stable/c/ad72e2566643fff7f01666d845fb026898155e1f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-97938","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97938","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9ec52099e4b8678a60e9f93e41ad87885d64f3e6 ad72e2566643fff7f01666d845fb026898155e1f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9ec52099e4b8678a60e9f93e41ad87885d64f3e6 9a17b0e053197a6a42cdc75e75a35b17aa662088 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9ec52099e4b8678a60e9f93e41ad87885d64f3e6 5a88f78df753993469dab4d1831f8fb4256a9468 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2.6.19","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 2.6.19 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.53 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.7 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc3 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"97938","cve":"CVE-2026-97938","epss":"0.001980000","percentile":"0.085920000","score_date":"2026-09-27","updated_at":"2026-09-28 00:02:24"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["include/linux/sched.h","include/linux/sched/signal.h","init/main.c","kernel/reboot.c","kernel/signal.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"ad72e2566643fff7f01666d845fb026898155e1f","status":"affected","version":"9ec52099e4b8678a60e9f93e41ad87885d64f3e6","versionType":"git"},{"lessThan":"9a17b0e053197a6a42cdc75e75a35b17aa662088","status":"affected","version":"9ec52099e4b8678a60e9f93e41ad87885d64f3e6","versionType":"git"},{"lessThan":"5a88f78df753993469dab4d1831f8fb4256a9468","status":"affected","version":"9ec52099e4b8678a60e9f93e41ad87885d64f3e6","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["include/linux/sched.h","include/linux/sched/signal.h","init/main.c","kernel/reboot.c","kernel/signal.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"2.6.19"},{"lessThan":"2.6.19","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.53","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.7","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc3","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.53","versionStartIncluding":"2.6.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.7","versionStartIncluding":"2.6.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc3","versionStartIncluding":"2.6.19","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nreboot: fix cad_pid use-after-free race\n\ncad_pid is a single kernel-wide struct pid pointer. proc_do_cad_pid()\nreads it and passes it to pid_vnr() without protecting the lifetime of\nthe referenced struct pid. A concurrent writer can replace cad_pid and\ndrop the final reference to the old struct pid after the reader has\nloaded the pointer but before pid_vnr() has finished dereferencing it,\ncausing a use-after-free.\n\nkill_cad_pid() has the same lifetime race when it passes cad_pid to\nkill_pid().\n\nAt the time this issue was reported, an unprivileged user could reach the\nsysctl through user and PID namespaces because cad_pid was registered in\npid_table[]. Moving cad_pid back to the global reboot sysctl table\ncorrected that namespace and permission mismatch, but did not fix the\nunderlying lifetime race.\n\nFix this by treating cad_pid as an RCU-protected pointer at both read\nsites and by waiting for a grace period before dropping the old reference\non the write side.\n\ncall_rcu(&old_pid->rcu, ...) cannot be used here because free_pid()\nalso queues pid->rcu; queueing the same rcu_head twice can corrupt the\nRCU callback list.\n\nOriginal KASAN crash stack:\n  kernel/pid.c:545 pid_nr_ns()        # reads freed pid->level\n  kernel/pid.c:556 pid_vnr()          # calls pid_nr_ns()\n  kernel/pid.c:775 proc_do_cad_pid()  # calls pid_vnr(cad_pid)"}],"providerMetadata":{"dateUpdated":"2026-09-25T10:22:51.720Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/ad72e2566643fff7f01666d845fb026898155e1f"},{"url":"https://git.kernel.org/stable/c/9a17b0e053197a6a42cdc75e75a35b17aa662088"},{"url":"https://git.kernel.org/stable/c/5a88f78df753993469dab4d1831f8fb4256a9468"}],"title":"reboot: fix cad_pid use-after-free race","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-97938","datePublished":"2026-09-25T10:22:51.720Z","dateReserved":"2026-09-25T10:18:58.204Z","dateUpdated":"2026-09-25T10:22:51.720Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-25 11:17:21","lastModifiedDate":"2026-09-25 11:17:21","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"97938","Ordinal":"1","Title":"reboot: fix cad_pid use-after-free race","CVE":"CVE-2026-97938","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"97938","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nreboot: fix cad_pid use-after-free race\n\ncad_pid is a single kernel-wide struct pid pointer. proc_do_cad_pid()\nreads it and passes it to pid_vnr() without protecting the lifetime of\nthe referenced struct pid. A concurrent writer can replace cad_pid and\ndrop the final reference to the old struct pid after the reader has\nloaded the pointer but before pid_vnr() has finished dereferencing it,\ncausing a use-after-free.\n\nkill_cad_pid() has the same lifetime race when it passes cad_pid to\nkill_pid().\n\nAt the time this issue was reported, an unprivileged user could reach the\nsysctl through user and PID namespaces because cad_pid was registered in\npid_table[]. Moving cad_pid back to the global reboot sysctl table\ncorrected that namespace and permission mismatch, but did not fix the\nunderlying lifetime race.\n\nFix this by treating cad_pid as an RCU-protected pointer at both read\nsites and by waiting for a grace period before dropping the old reference\non the write side.\n\ncall_rcu(&old_pid->rcu, ...) cannot be used here because free_pid()\nalso queues pid->rcu; queueing the same rcu_head twice can corrupt the\nRCU callback list.\n\nOriginal KASAN crash stack:\n  kernel/pid.c:545 pid_nr_ns()        # reads freed pid->level\n  kernel/pid.c:556 pid_vnr()          # calls pid_nr_ns()\n  kernel/pid.c:775 proc_do_cad_pid()  # calls pid_vnr(cad_pid)","Type":"Description","Title":"reboot: fix cad_pid use-after-free race"}]}}}