CVE-2026-80778

Summary

In the Linux kernel, the following vulnerability has been resolved:

futex/pi: Reject cross-mm private futex owners

A private futex key borrows the waiter's mm without taking an mm_users reference. Nevertheless, attach_to_pi_owner() currently accepts an owner from a different address space and copies the private key into the owner's PI state.

When that owner exits, exit_pi_state_list() uses the saved key to find the hash bucket and acquires a reference to the waiter's private hash. If the last user of the waiter's mm exits concurrently, futex_hash_free() frees the hash while the owner still uses its bucket and reference.

Prevent this by validating in attach_to_pi_owner() that, for private futexes, the owner mm and waiter mm are the same. Perform the check with the owner's pi_lock held and after validating owner::futex::state to serialize against a concurrent PI-state exit cleanup.

[ tglx: Amended comment ]

Affected Software

VendorProductVersion RangeStatus
LinuxLinux80367ad01d93ac781b0e1df246edaf006928002f < 2b92e5562653b5293529f63b0300837d9dcedbd7affected
LinuxLinux80367ad01d93ac781b0e1df246edaf006928002f < f7fb3e07752688842cbe0b85cf0d98c2fbf76b68affected
LinuxLinux80367ad01d93ac781b0e1df246edaf006928002f < 43b148d796aa338858792d0167cebdc12b8cb4b9affected
LinuxLinux80367ad01d93ac781b0e1df246edaf006928002f < 59b3732f95dda1fbd2234514d35f4fb6b5bb6d85affected
LinuxLinux6.16affected
LinuxLinux0 < 6.16unaffected
LinuxLinux6.18.47 <= 6.18.*unaffected
LinuxLinux7.1.11 <= 7.1.*unaffected
LinuxLinux7.2.1 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References