Answer in brief
CVE-2026-97949 records a Unknown severity vulnerability in configfs: unhash the dentry before dropping the item in rmdir. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7063fbf2261194f72ee75afca67b3b38b554b5fa <5d7cbfb65e47cc71d5d94d87d5d0d1679080f3eb || >=7063fbf2261194f72ee75afca67b3b38b554b5fa <925d8564f1b2d9b46c5ab63b9bc942cea006da9b || >=7063fbf2261194f72ee75afca67b3b38b554b5fa <f06c2d26d1999d37e93299db0ecead04ca7d0b9f | 5d7cbfb65e47cc71d5d94d87d5d0d1679080f3eb, 925d8564f1b2d9b46c5ab63b9bc942cea006da9b, f06c2d26d1999d37e93299db0ecead04ca7d0b9f |
| Linux/Linuxgeneric | 2.6.16 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: configfs: unhash the dentry before dropping the item in rmdir configfs_get_config_item() treats a hashed dentry as proof that sd->s_element is a live config_item. configfs_rmdir() breaks that: simple_rmdir() leaves the dentry hashed, the last reference to the item is dropped right after, and the dentry is only unhashed by d_delete() once ->rmdir() has returned. configfs_symlink() resolves its target holding no lock on it, so get_target() can land in that window: BUG: KASAN: slab-use-after-free in config_item_get+0x26/0x90 get_target fs/configfs/symlink.c:128 [inline] configfs_symlink+0x4ab/0x1030 fs/configfs/symlink.c:185 Unhash in configfs_remove_dir(), while the item is still guaranteed to be there. A reference obtained just before that stays harmless, as create_link() rechecks CONFIGFS_USET_DROPPING, already set by configfs_detach_prep(). Both configfs_unregister_subsystem() paths d_drop() after detaching, so this only makes rmdir match them.
Quoted source text, attributed separately from HOL analysis.