← All Advisories

CVE-2026-97938

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97938

Key Details

CVECVE-2026-97938
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

reboot: fix cad_pid use-after-free race

cad_pid is a single kernel-wide struct pid pointer. proc_do_cad_pid()

reads it and passes it to pid_vnr() without protecting the lifetime of

the referenced struct pid. A concurrent writer can replace cad_pid and

drop the final reference to the old struct pid after the reader has

loaded the pointer but before pid_vnr() has finished dereferencing it,

causing a use-after-free.

kill_cad_pid() has the same lifetime race when it passes cad_pid to

kill_pid().

At the time this issue was reported, an unprivileged user could reach the

sysctl through user and PID namespaces because cad_pid was registered in

pid_table[]. Moving cad_pid back to the global reboot sysctl table

corrected that namespace and permission mismatch, but did not fix the

underlying lifetime race.

Fix this by treating cad_pid as an RCU-protected pointer at both read

sites and by waiting for a grace period before dropping the old reference

on the write side.

call_rcu(&old_pid->rcu, ...) cannot be used here because free_pid()

also queues pid->rcu; queueing the same rcu_head twice can corrupt the

RCU callback list.

Original KASAN crash stack:

kernel/pid.c:545 pid_nr_ns() # reads freed pid->level

kernel/pid.c:556 pid_vnr() # calls pid_nr_ns()

kernel/pid.c:775 proc_do_cad_pid() # calls pid_vnr(cad_pid) (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97938
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97938