Linux Kernel Vulnerability in OverlayFS Affecting Dentry Creation
CVE-2026-89767
What is CVE-2026-89767?
The vulnerability in the Linux kernel's OverlayFS allows unprivileged users to exploit a flaw in the dentry creation process. This issue occurs due to improper handling of casefold consistency, which may cause the system to enter a deadlock state when attempting to create directories. Malicious users can craft specific conditions leading to multiple erroneous calls to end_creating(), which results in the unlocking of directory locks that are not held. This flaw can potentially disrupt normal operations and lead to denial-of-service scenarios, making it critical for affected systems to apply necessary patches to prevent exploitation.
Affected Version(s)
Linux dfc7da402ccc92d6e4b01a4778a3f15f2496b9af < 2fa220bc0f84597cb6de665e5b5021c5901ddf00
Linux dfc7da402ccc92d6e4b01a4778a3f15f2496b9af
Linux dfc7da402ccc92d6e4b01a4778a3f15f2496b9af < 077ab8985ee278c3d8618182d335b0f0cd919e16