Bug 2541345 (CVE-2026-98117) - CVE-2026-98117 kernel: cachefiles: Fix potential UAF/KASAN warning
Summary: CVE-2026-98117 kernel: cachefiles: Fix potential UAF/KASAN warning
Keywords:
Status: NEW
Alias: CVE-2026-98117
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 11:29 UTC by OSIDB Bzimport
Modified: 2026-09-28 12:54 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 11:29:53 UTC
In the Linux kernel, the following vulnerability has been resolved:

cachefiles: Fix potential UAF/KASAN warning

Currently, trace_cachefiles_coherency() is being passed a pointer to a
__be64 lain over the coherency data in struct cachefiles_xattr so that it
can display the first 8 bytes.  However, the data is of variable length and
could even be 0 bytes.  This could lead to a UAF or KASAN warning.

Fix this by making sure the buffer has room for at least 8 bytes and that
those 8 bytes are pre-cleared.

Further, those bytes are not 8-byte aligned, so fix the tracepoint to
extract the data as four 2-byte words (they are 2-byte aligned) and
reassemble the __be64.  The compiler will convert this into a single 8-byte
load where the CPU supports it.


Note You need to log in before you can comment on or make changes to this bug.