CVE-2026-89767

Source
https://cve.org/CVERecord?id=CVE-2026-89767
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89767.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89767
Downstream
Published
2026-09-11T19:47:07Z
Modified
2026-09-14T03:46:32Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ovl: fix double end_creating() on the casefold-mismatch path
Details

In the Linux kernel, the following vulnerability has been resolved:

ovl: fix double end_creating() on the casefold-mismatch path

ovl_create_real() releases the new dentry twice when the casefold consistency check fails. The S_IFDIR branch calls end_creating() and sets err, then falls through to the common out: label which calls end_creating() on the same dentry again:

case S_IFDIR:
	newdentry = ovl_do_mkdir(ofs, dir, newdentry, attr->mode);
	err = PTR_ERR_OR_ZERO(newdentry);
	if (!err && ofs->casefold != ovl_dentry_casefolded(newdentry)) {
		pr_warn_ratelimited(...);
		end_creating(newdentry);	/* first */
		err = -EINVAL;
	}
	break;
...
if (err)
	goto out;
...

out: if (err) { end_creating(newdentry); /* second, same dentry */ return ERR_PTR(err); }

end_creating() is end_dirop(), which does inode_unlock() on the parent and dput() on the dentry, so the parent directory's i_rwsem is unlocked twice and the dentry is put twice. The second unlock releases a lock that is not held, which is what wedges every later creation under that parent, and the second dput() drops a reference that was never taken.

The branch was added by commit dfc7da402ccc ("ovl: Check for casefold consistency when creating new dentries") as a bare dput(), which already released the reference twice; commit fe497f0759e0 ("VFS: change vfs_mkdir() to unlock on failure.") converted both sites to end_creating(), adding the double unlock.

This is reachable by an unprivileged user. The casefold consistency of the layers is validated at mount time in ovl_parse_layer(), and again on every lookup in ovl_lookup_single(), but ofs->workdir is the internal "work" subdirectory created inside the user-supplied workdir, and that subdirectory is not re-checked. Marking it casefolded after the mount therefore makes every ovl_create_temp() inherit the wrong state - and that path reaches ovl_create_real() through ovl_start_creating_temp(), which uses start_creating() with a generated name and so never runs the lookup-time check.

unshare -Urm mount -t tmpfs -o casefold=utf8-12.1.0 tmpfs mnt mkdir -p mnt/lower/d mnt/upper mnt/work mnt/merged mount -t overlay ovl -o lowerdir=mnt/lower,
upperdir=mnt/upper,workdir=mnt/work mnt/merged chattr +F mnt/work/work mkdir mnt/merged/d/sub # directory copy-up

overlayfs: wrong inherited casefold (work/#5)

and the next copy-up blocks forever on the parent's i_rwsem:

mkdir D start_creating+0x65/0xb0 ovl_start_creating_temp+0xb0/0xe0 [overlay] ovl_create_temp+0xa3/0x1d0 [overlay] ovl_copy_up_one+0x1f1c/0x21c0 [overlay] ovl_copy_up_flags+0xf5/0x140 [overlay] ovl_create_object+0xb7/0x220 [overlay] ovl_mkdir+0x23/0x40 [overlay]

Drop the end_creating() from the branch and let out: own the cleanup, which is what every other error path in this function already does.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89767.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
dfc7da402ccc92d6e4b01a4778a3f15f2496b9af
Fixed
2fa220bc0f84597cb6de665e5b5021c5901ddf00
Fixed
b1aa8ab78a8e87aee9e306971465408e059f839a
Fixed
077ab8985ee278c3d8618182d335b0f0cd919e16

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89767.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.18.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89767.json"