ZeroHour

CVE-2026-89767

mass

Double lock release in Linux kernel overlayfs casefold path causes local DoS

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

The Linux kernel's overlayfs ovl_create_real() calls end_creating() twice on the casefold-mismatch error path, which double-unlocks the parent directory's i_rwsem and double-drops the new dentry's reference via dput(). An unprivileged local user can trigger it by mounting an overlayfs inside a user namespace and marking the internal 'work' subdirectory as casefolded (chattr +F) after mount — a state that escapes both the mount-time and lookup-time casefold consistency checks — then performing a directory copy-up such as mkdir. The demonstrated impact is a local denial of service: every later creation under the affected parent blocks forever on a lock that is no longer held, while the extra dput() releases a reference that was never taken, a memory-management error consistent with the high confidentiality/integrity ratings in the CVSS 3.1 score of 7.8. Any system running a kernel containing the relevant overlayfs casefold commits and permitting unprivileged user namespaces and overlay mounts is affected. No public proof of concept is known, the flaw is not in the CISA KEV catalog, and no exploitation in the wild has been reported.

What to do: Patch to a kernel release containing this overlayfs fix as soon as your distribution ships it. As an interim mitigation on internet-facing or multi-user Linux hosts, restrict unprivileged user namespaces (e.g., sysctl user.max_user_namespaces=0 or kernel.unprivileged_userns_clone=0, depending on distro) or otherwise disallow unprivileged overlayfs mounts, which blocks the described trigger path. For detection, monitor dmesg for the 'wrong inherited casefold' overlayfs warning and for tasks hung in ovl_start_creating_temp/ovl_copy_up on overlay mounts.

Affected
Linux kernel (overlayfs)
Estimated exposure
masspotentially hundreds of millions of devices (any recent-kernel Linux system with unprivileged user namespaces enabled) — clearly an estimate — The Linux kernel ships on billions of devices (Android alone has roughly 3 billion active devices, plus the majority of servers and a large desktop install base), overlayfs and unprivileged user namespaces are enabled by default on most…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In the Linux kernel, the following vulnerability has been resolved: ovl: fix double end_creating() on the casefold-mismatch path ovl_create_real() releases the new dentry twice when the casefold consistency check fails. The S_IFDIR branch calls end_creating() and sets err, then falls through to the common out: label which calls end_creating() on the same dentry again: case S_IFDIR: newdentry = ovl_do_mkdir(ofs, dir, newdentry, attr->mode); err = PTR_ERR_OR_ZERO(newdentry); if (!err && ofs->casefold != ovl_dentry_casefolded(newdentry)) { pr_warn_ratelimited(...); end_creating(newdentry); /* first */ err = -EINVAL; } break; ... if (err) goto out; ... out: if (err) { end_creating(newdentry); /* second, same dentry */ return ERR_PTR(err); } end_creating() is end_dirop(), which does inode_unlock() on the parent and dput() on the dentry, so the parent directory's i_rwsem is unlocked twice and the dentry is put twice. The second unlock releases a lock that is not held, which is what wedges every later creation under that parent, and the second dput() drops a reference that was never taken. The branch was added by commit dfc7da402ccc ("ovl: Check for casefold consistency when creating new dentries") as a bare dput(), which already released the reference twice; commit fe497f0759e0 ("VFS: change vfs_mkdir() to unlock on failure.") converted both sites to end_creating(), adding the double unlock. This is reachable by an unprivileged user. The casefold consistency of the layers is validated at mount time in ovl_parse_layer(), and again on every lookup in ovl_lookup_single(), but ofs->workdir is the internal "work" subdirectory created inside the user-supplied workdir, and that subdirectory is not re-checked. Marking it casefolded after the mount therefore makes every ovl_create_temp() inherit the wrong state - and that path reaches ovl_create_real() through ovl_start_creating_temp(), which uses start_creating() with a generated name and so never runs the lookup-time check. unshare -Urm mount -t tmpfs -o casefold=utf8-12.1.0 tmpfs mnt mkdir -p mnt/lower/d mnt/upper mnt/work mnt/merged mount -t overlay ovl -o lowerdir=mnt/lower,\ upperdir=mnt/upper,workdir=mnt/work mnt/merged chattr +F mnt/work/work mkdir mnt/merged/d/sub # directory copy-up overlayfs: wrong inherited casefold (work/#5) and the next copy-up blocks forever on the parent's i_rwsem: mkdir D start_creating+0x65/0xb0 ovl_start_creating_temp+0xb0/0xe0 [overlay] ovl_create_temp+0xa3/0x1d0 [overlay] ovl_copy_up_one+0x1f1c/0x21c0 [overlay] ovl_copy_up_flags+0xf5/0x140 [overlay] ovl_create_object+0xb7/0x220 [overlay] ovl_mkdir+0x23/0x40 [overlay] Drop the end_creating() from the branch and let out: own the cleanup, which is what every other error path in this function already does.

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.