CVE-2026-80777
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
futex/pi: Plug private futex exec() race
The check for private futexes whether the waiter's mm, which is stored in the futex_key and copied into the pi_state, is the same as the owner's mm is not sufficient for exec(). exec() has a gap where the mm check fails to give the correct answer:
exec() … exec_release_mm() futex_exec_release() tsk::futex::exit_state = EXITING; cleanup_robust_list();
… old_mm = tsk::mm;tsk::futex::exit_state = OK;- tsk::mm = ->mm;
Between #1 and #2 the check for the mm is wrong as that mm is about to be swapped out and eventually freed.
Plug this gap by:
Setting tsk::futex::exit_state to FUTEX_STATE_DEAD in futex_exec_release()
Setting tsk::futex::exit_state to FUTEX_STATE_OK after the mm has been switched.
From a futex point of view the task is dead after it finished the robust list cleanup up to the point where it sets the state to OK again.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 80367ad01d93ac781b0e1df246edaf006928002f < fdf538b2e69653ff740e84042245018e5680cd7b | affected |
| Linux | Linux | 80367ad01d93ac781b0e1df246edaf006928002f < 0478bc6bf197629fea0331d65b39eeea043c6cf0 | affected |
| Linux | Linux | 80367ad01d93ac781b0e1df246edaf006928002f < d7944cee62ec6cca1c90780a766960a57d3b4bb8 | affected |
| Linux | Linux | 80367ad01d93ac781b0e1df246edaf006928002f < c5f0bc9fd1cec4a00400cc727fcde03e0fde17cc | affected |
| Linux | Linux | 6.16 | affected |
| Linux | Linux | 0 < 6.16 | unaffected |
| Linux | Linux | 6.18.47 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.11 <= 7.1.* | unaffected |
| Linux | Linux | 7.2.1 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/fdf538b2e69653ff740e84042245018e5680cd7b
- https://git.kernel.org/stable/c/0478bc6bf197629fea0331d65b39eeea043c6cf0
- https://git.kernel.org/stable/c/d7944cee62ec6cca1c90780a766960a57d3b4bb8
- https://git.kernel.org/stable/c/c5f0bc9fd1cec4a00400cc727fcde03e0fde17cc
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.