← All Advisories

CVE-2026-97410

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97410

Key Details

CVECVE-2026-97410
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

netconsole: take target_cleanup_list_lock in drop_netconsole_target()

drop_netconsole_target() unlinks the target while only holding

target_list_lock. However, when the underlying interface has been

unregistered, netconsole_netdev_event() moves the target from

target_list to target_cleanup_list, and netconsole_process_cleanups_core()

walks that list under target_cleanup_list_lock only.

If a user removes the configfs target at the same time the cleanup

worker is iterating target_cleanup_list, list_del() can corrupt the list

because the two paths take disjoint locks while operating on the same

list node.

Acquire target_cleanup_list_lock around the list_del() so the unlink is

serialised against netconsole_process_cleanups_core() regardless of

which list the target currently belongs to. The state transition that

downgrades STATE_DEACTIVATED to STATE_DISABLED is left intact and is

performed under the same combined locking, preserving the existing

ordering with resume_target(). (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97410
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97410