← All Advisories

CVE-2026-97901

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97901

Key Details

CVECVE-2026-97901
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

genetlink: pin family module during policy dump

The generic netlink controller's policy dump keeps pointers to the target

family's operation and policy tables in its callback state. A dump may be

split across multiple skbs and remain pending after the initial request.

Netlink pins the module which owns the dump callback, but in this case

that is the controller's owner rather than the target family's owner. The

target family can consequently be unregistered and its module unloaded

while a policy dump is pending. Advancing the dump then dereferences

policy memory from the unloaded module.

Take a reference to the target family's module when the dump starts.

Drop it from the error and done paths. This matches the lifetime for which

the dump context retains the family and policy pointers. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97901
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97901