In the Linux kernel, the following vulnerability has been resolved:
netconsole: Acquire su_mutex before navigating configs hierarchy
There is a race between operations that iterate over the userdata cg_children list and concurrent add/remove of userdata items through configfs. The update_userdata() function iterates over the nt->userdata_group.cg_children list, and count_extradata_entries() also iterates over this same list to count nodes.
Quoting from Documentation/filesystems/configfs.rst: > A subsystem can navigate the cg_children list and the ci_parent pointer > to see the tree created by the subsystem. This can race with configfs' > management of the hierarchy, so configfs uses the subsystem mutex to > protect modifications. Whenever a subsystem wants to navigate the > hierarchy, it must do so under the protection of the subsystem > mutex.
Without proper locking, if a userdata item is added or removed concurrently while these functions are iterating, the list can be accessed in an inconsistent state. For example, the list_for_each() loop can reach a node that is being removed from the list by list_del_init() which sets the nodes' .next pointer to point to itself, so the loop will never end (or reach the WARN_ON_ONCE in update_userdata() ).
Fix this by holding the configfs subsystem mutex (su_mutex) during all operations that iterate over cg_children. This includes: - userdatum_value_store() which calls update_userdata() to iterate over cg_children - All sysdata_*_enabled_store() functions which call count_extradata_entries() to iterate over cg_children
The su_mutex must be acquired before dynamic_netconsole_mutex to avoid potential lock ordering issues, as configfs operations may already hold su_mutex when calling into our code.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Dec 16, 2025 |
| Ubuntu | — | Upgrade linux-image-6.17.0-1007-oracleUpgrade linux-image-6.17.0-1008-azureUpgrade linux-image-6.17.0-1011-oemUpgrade linux-image-virtualUpgrade linux-image-gcpUpgrade linux-image-6.17.0-1006-realtimeUpgrade linux-image-generic-64kUpgrade linux-image-generic-6.17Upgrade linux-image-6.17.0-14-generic-64kUpgrade linux-image-6.17.0-1007-gcpUpgrade linux-image-azure-6.17Upgrade linux-image-6.17.0-1007-aws-64kUpgrade linux-image-6.17.0-1007-gcp-64kUpgrade linux-image-genericUpgrade linux-image-azureUpgrade linux-image-6.17.0-1007-awsUpgrade linux-image-awsUpgrade linux-image-6.17.0-14-genericUpgrade linux-image-oracle-6.17Upgrade linux-image-generic-64k-6.17Upgrade linux-image-6.17.0-1008-raspiUpgrade linux-image-6.17.0-1007-oracle-64kUpgrade linux-image-oracle-64kUpgrade linux-image-oracle-64k-6.17Upgrade linux-image-oem-6.17Upgrade linux-image-gcp-64k-6.17Upgrade linux-image-raspi-6.17Upgrade linux-image-gcp-64kUpgrade linux-image-aws-6.17Upgrade linux-image-aws-64k-6.17Upgrade linux-image-realtime-6.17Upgrade linux-image-realtimeUpgrade linux-image-oracleUpgrade linux-image-gcp-6.17Upgrade linux-image-virtual-6.17Upgrade linux-image-aws-64kUpgrade linux-image-raspi | Feb 13, 2026 | Feb 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub