Description
In the Linux kernel, the following vulnerability has been resolved:

fs/resctrl: Prevent use-after-free in rdtgroup_kn_put()

A struct rdtgroup is reference counted via rdtgroup::waitcount. Callers that
need the structure to remain valid across a sleep (while waiting on acquiring
rdtgroup_mutex) take a reference with rdtgroup_kn_get() and release it with
rdtgroup_kn_put().

The release path is intended to serve as the fallback freer: if the count
drops to zero and the group has already been marked RDT_DELETED,
rdtgroup_kn_put() frees the structure.

The bulk teardown paths free_all_child_rdtgrp() and rmdir_all_sub() resulting
from a resctrl directory remove or resctrl fs unmount act as the primary
freer: they hold rdtgroup_mutex and free each rdtgroup whose waitcount is
zero, otherwise they set RDT_DELETED and leave the freeing to the last waiter.

These two freers race. rdtgroup_kn_put() commits waitcount == 0 with
atomic_dec_and_test() outside rdtgroup_mutex, then reads rdtgroup::flags.
Between those two operations a concurrent caller of free_all_child_rdtgrp()
or rmdir_all_sub() (which holds the mutex) can observe waitcount == 0 via
atomic_read(), call rdtgroup_remove(), and kfree() the structure.

The subsequent read of rdtgroup::flags in rdtgroup_kn_put() is then
a use-after-free, and the structure may even be freed twice if the freed
memory happens to satisfy the RDT_DELETED flag check.

Replace the bare atomic_dec_and_test() with atomic_dec_and_mutex_lock() so
that the decrement-to-zero takes rdtgroup_mutex before the count becomes
globally visible. The inspection of rdtgroup::flags then runs under the same
mutex held by the bulk freers, making the two paths mutually exclusive.

The common case where the count does not reach zero remains lock-free. Defer
kernfs_unbreak_active_protection() until after the mutex is dropped since
kernfs active protections functionally wrap rdtgroup_mutex. Remove resource
group, which in turn drops its kernfs reference, after kernfs protection is
restored.

[ bp: Split the commit messsages into smaller, easier-parseable paragraphs. ]
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free Leading to Potential Kernel Exploit
Action: Immediate Patch
AI Analysis

Impact

A race condition in the Linux kernel’s resctrl subsystem allows a use‑after‑free bug when the reference counter for an rdtgroup structure is decremented outside the mutex protecting the object. If two free paths execute concurrently, the structure may be freed and then accessed again, which can lead to arbitrary kernel code execution or denial of service. This flaw is a classic memory corruption vulnerability that is exploitable once the attacker can trigger the concurrent release and teardown operations.

Affected Systems

The vulnerability affects any Linux system running a kernel that implements the resctrl feature without the protective change. No specific kernel versions are listed, so all releases that contain the unpatched resctrl code are potentially impacted. The issue is present in the core kernel, not an add‑on module.

Risk and Exploitability

The EPSS score is less than 1 % and the flaw is not currently listed in the CISA KEV catalog, indicating low to moderate evidence of active exploitation. The CVSS score is not provided, but use‑after‑free bugs usually carry a high severity rating. Attackers would need the ability to perform concurrent resctrl operations—typically via privileged userspace processes or scripts that write to resctrl directories while the filesystem is being unmounted or cleaned up. Based on the description, the likely attack vector is local privileged access rather than remote exploitation.

Generated by OpenCVE AI on September 19, 2026 at 07:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a patched release that replaces atomic_dec_and_test with atomic_dec_and_mutex_lock in rdtgroup_kn_put()
  • If a kernel update is not immediately possible, manually apply the patch from the provided upstream commits, rebuild the kernel, and reboot
  • As a temporary workaround, unmount the /sys/fs/resctrl filesystem or disable the resctrl feature until the patch is applied to prevent concurrent tear‑down operations from occurring

Generated by OpenCVE AI on September 19, 2026 at 07:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-410
CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fs/resctrl: Prevent use-after-free in rdtgroup_kn_put() A struct rdtgroup is reference counted via rdtgroup::waitcount. Callers that need the structure to remain valid across a sleep (while waiting on acquiring rdtgroup_mutex) take a reference with rdtgroup_kn_get() and release it with rdtgroup_kn_put(). The release path is intended to serve as the fallback freer: if the count drops to zero and the group has already been marked RDT_DELETED, rdtgroup_kn_put() frees the structure. The bulk teardown paths free_all_child_rdtgrp() and rmdir_all_sub() resulting from a resctrl directory remove or resctrl fs unmount act as the primary freer: they hold rdtgroup_mutex and free each rdtgroup whose waitcount is zero, otherwise they set RDT_DELETED and leave the freeing to the last waiter. These two freers race. rdtgroup_kn_put() commits waitcount == 0 with atomic_dec_and_test() outside rdtgroup_mutex, then reads rdtgroup::flags. Between those two operations a concurrent caller of free_all_child_rdtgrp() or rmdir_all_sub() (which holds the mutex) can observe waitcount == 0 via atomic_read(), call rdtgroup_remove(), and kfree() the structure. The subsequent read of rdtgroup::flags in rdtgroup_kn_put() is then a use-after-free, and the structure may even be freed twice if the freed memory happens to satisfy the RDT_DELETED flag check. Replace the bare atomic_dec_and_test() with atomic_dec_and_mutex_lock() so that the decrement-to-zero takes rdtgroup_mutex before the count becomes globally visible. The inspection of rdtgroup::flags then runs under the same mutex held by the bulk freers, making the two paths mutually exclusive. The common case where the count does not reach zero remains lock-free. Defer kernfs_unbreak_active_protection() until after the mutex is dropped since kernfs active protections functionally wrap rdtgroup_mutex. Remove resource group, which in turn drops its kernfs reference, after kernfs protection is restored. [ bp: Split the commit messsages into smaller, easier-parseable paragraphs. ]
Title fs/resctrl: Prevent use-after-free in rdtgroup_kn_put()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:13.077Z

Reserved: 2026-09-17T16:02:15.085Z

Link: CVE-2026-93100

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:04.223

Modified: 2026-09-17T17:18:04.223

Link: CVE-2026-93100

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:00:13Z

Weaknesses