Ad

CVE-2026-89767

NONE EPSS 0.18%
Обновлено 11 сентября 2026
Linux
Параметр Значение
Поставщик Linux
Публичный эксплойт Нет

В ядре Linux устранена следующая уязвимость: ovl: исправлено двойное end_creating() на пути несоответствия регистра ovl_create_real() освобождает новую дентри дважды, когда сворачивается проверка целостности не удалась. Ветка S_IFDIR вызывает end_creating() и устанавливает ошибку, затем переходит к общему выходу: метка, которая вызывает end_creating() снова в том же дентре: случай S_IFDIR: newdentry = ovl_do_mkdir(ofs, dir, newdentry, attr->mode); ошибка = PTR_ERR_OR_ZERO(newdentry); if (!err && ofs->casefold != ovl_dentry_casefolded(newdentry)) { pr_warn_ratelimited(...); end_creating (newdentry); /* первый */ ошибка = -ЭИНВАЛ; } перерыв; ... если (ошибка) выйти; ... выход: если (ошибка) { end_creating (newdentry); /* вторая, та же самая зубная щель */ вернуть ERR_PTR(ошибка); } end_creating() — это end_dirop(), который выполняет inode_unlock() для родительского объекта. и dput() на dentry, поэтому i_rwsem родительского каталога разблокирован дважды и зубной ряд ставится дважды. Вторая разблокировка снимает блокировку это не соблюдается, и именно это вклинивает каждое последующее творение под это родительский, а второй dput() удаляет ссылку, которая никогда не использовалась.

Ветка была добавлена коммитом dfc7da402ccc («ovl: Проверьте наличие регистра согласованность при создании новых dentries") как голый dput(), который уже дважды выпустил ссылку; commit fe497f0759e0 ("VFS: изменить vfs_mkdir() для разблокировки в случае сбоя.") преобразовал оба сайта в end_creating(), добавляющая двойную разблокировку. Это доступно непривилегированному пользователю. Последовательность случаев слои проверяются во время монтирования в ovl_parse_layer() и снова каждый поиск в ovl_lookup_single(), но ofs->workdir является внутренним подкаталог «work», созданный внутри предоставленного пользователем рабочего каталога, и этот подкаталог не проверяется повторно.

Маркировка в сложенном виде после крепления поэтому каждый ovl_create_temp() наследует неправильное состояние - и этот путь достигает ovl_create_real() через ovl_start_creating_temp(), который использует start_creating() со сгенерированным именем и поэтому никогда не запускает проверка времени поиска. отменить долю - хм mount -t tmpfs -o casefold=utf8-12.1.0 tmpfs mnt mkdir -p mnt/нижний/d mnt/верхний mnt/work mnt/merged mount -t overlay ovl -o lowdir=mnt/lower,\ Upperdir=mnt/upper,workdir=mnt/work mnt/merged чаттр +F мнт/работа/работа mkdir mnt/merged/d/sub # копирование каталога overlayfs: неправильный унаследованный регистр (работа/#5) и следующая копия навсегда блокируется в родительском i_rwsem: mkdir D start_creating+0x65/0xb0 ovl_start_creating_temp+0xb0/0xe0 [оверлей] ovl_create_temp+0xa3/0x1d0 [оверлей] ovl_copy_up_one+0x1f1c/0x21c0 [наложение] ovl_copy_up_flags+0xf5/0x140 [оверлей] ovl_create_object+0xb7/0x220 [оверлей] ovl_mkdir+0x23/0x40 [наложение] Удалите end_creating() из ветки и выпустите: владейте очисткой, то же самое уже делает любой другой путь ошибки в этой функции.

Показать оригинальное описание (EN)

In the Linux kernel, the following vulnerability has been resolved: ovl: fix double end_creating() on the casefold-mismatch path ovl_create_real() releases the new dentry twice when the casefold consistency check fails. The S_IFDIR branch calls end_creating() and sets err, then falls through to the common out: label which calls end_creating() on the same dentry again: case S_IFDIR: newdentry = ovl_do_mkdir(ofs, dir, newdentry, attr->mode); err = PTR_ERR_OR_ZERO(newdentry); if (!err && ofs->casefold != ovl_dentry_casefolded(newdentry)) { pr_warn_ratelimited(...); end_creating(newdentry); /* first */ err = -EINVAL; } break; ... if (err) goto out; ... out: if (err) { end_creating(newdentry); /* second, same dentry */ return ERR_PTR(err); } end_creating() is end_dirop(), which does inode_unlock() on the parent and dput() on the dentry, so the parent directory's i_rwsem is unlocked twice and the dentry is put twice. The second unlock releases a lock that is not held, which is what wedges every later creation under that parent, and the second dput() drops a reference that was never taken. The branch was added by commit dfc7da402ccc ("ovl: Check for casefold consistency when creating new dentries") as a bare dput(), which already released the reference twice; commit fe497f0759e0 ("VFS: change vfs_mkdir() to unlock on failure.") converted both sites to end_creating(), adding the double unlock. This is reachable by an unprivileged user. The casefold consistency of the layers is validated at mount time in ovl_parse_layer(), and again on every lookup in ovl_lookup_single(), but ofs->workdir is the internal "work" subdirectory created inside the user-supplied workdir, and that subdirectory is not re-checked. Marking it casefolded after the mount therefore makes every ovl_create_temp() inherit the wrong state - and that path reaches ovl_create_real() through ovl_start_creating_temp(), which uses start_creating() with a generated name and so never runs the lookup-time check. unshare -Urm mount -t tmpfs -o casefold=utf8-12.1.0 tmpfs mnt mkdir -p mnt/lower/d mnt/upper mnt/work mnt/merged mount -t overlay ovl -o lowerdir=mnt/lower,\ upperdir=mnt/upper,workdir=mnt/work mnt/merged chattr +F mnt/work/work mkdir mnt/merged/d/sub # directory copy-up overlayfs: wrong inherited casefold (work/#5) and the next copy-up blocks forever on the parent's i_rwsem: mkdir D start_creating+0x65/0xb0 ovl_start_creating_temp+0xb0/0xe0 [overlay] ovl_create_temp+0xa3/0x1d0 [overlay] ovl_copy_up_one+0x1f1c/0x21c0 [overlay] ovl_copy_up_flags+0xf5/0x140 [overlay] ovl_create_object+0xb7/0x220 [overlay] ovl_mkdir+0x23/0x40 [overlay] Drop the end_creating() from the branch and let out: own the cleanup, which is what every other error path in this function already does.