CVE-2026-97410
CVE CVE-2026-97410EUVD EUVD-2026-86023Published 2026-09-24T16:03:17.000ZLast changed 2026-09-25T12:43:44.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: netconsole: take target_cleanup_list_lock in drop_netconsole_target() drop_netconsole_target() unlinks the target while only holding target_list_lock. However, when the underlying interface has been unregistered, netconsole_netdev_event() moves the target from target_list to target_cleanup_list, and netconsole_process_cleanups_core() walks that list under target_cleanup_list_lock only. If a user removes the configfs target at the same time the cleanup worker is iterating target_cleanup_list, list_del() can corrupt the list because the two paths take disjoint locks while operating on the same list node. Acquire target_cleanup_list_lock around the list_del() so the unlink is serialised against netconsole_process_cleanups_core() regardless of which list the target currently belongs to. The state transition that downgrades STATE_DEACTIVATED to STATE_DISABLED is left intact and is performed under the same combined locking, preserving the existing ordering with resume_target().
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 97714695ef904a4bdba75ca2f339215c0ae2b1fa <91aeb87f052367a5a2743cc93777dfb4386f2f14; patch: 6.18.53; patch: 0; 6.12; 97714695ef904a4bdba75ca2f339215c0ae2b1fa <84592ee22f7d1583ce33aa733411ff36c7a1c44c; 97714695ef904a4bdba75ca2f339215c0ae2b1fa <fe8e6c0a2f28bdab14cdf7eff4dd9755d3793007; patch: 6.12.111; patch: 7.2
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.