CVE-2026-80778
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
futex/pi: Reject cross-mm private futex owners
A private futex key borrows the waiter's mm without taking an mm_users reference. Nevertheless, attach_to_pi_owner() currently accepts an owner from a different address space and copies the private key into the owner's PI state.
When that owner exits, exit_pi_state_list() uses the saved key to find the hash bucket and acquires a reference to the waiter's private hash. If the last user of the waiter's mm exits concurrently, futex_hash_free() frees the hash while the owner still uses its bucket and reference.
Prevent this by validating in attach_to_pi_owner() that, for private futexes, the owner mm and waiter mm are the same. Perform the check with the owner's pi_lock held and after validating owner::futex::state to serialize against a concurrent PI-state exit cleanup.
[ tglx: Amended comment ]
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 80367ad01d93ac781b0e1df246edaf006928002f < 2b92e5562653b5293529f63b0300837d9dcedbd7 | affected |
| Linux | Linux | 80367ad01d93ac781b0e1df246edaf006928002f < f7fb3e07752688842cbe0b85cf0d98c2fbf76b68 | affected |
| Linux | Linux | 80367ad01d93ac781b0e1df246edaf006928002f < 43b148d796aa338858792d0167cebdc12b8cb4b9 | affected |
| Linux | Linux | 80367ad01d93ac781b0e1df246edaf006928002f < 59b3732f95dda1fbd2234514d35f4fb6b5bb6d85 | affected |
| Linux | Linux | 6.16 | affected |
| Linux | Linux | 0 < 6.16 | unaffected |
| Linux | Linux | 6.18.47 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.11 <= 7.1.* | unaffected |
| Linux | Linux | 7.2.1 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/2b92e5562653b5293529f63b0300837d9dcedbd7
- https://git.kernel.org/stable/c/f7fb3e07752688842cbe0b85cf0d98c2fbf76b68
- https://git.kernel.org/stable/c/43b148d796aa338858792d0167cebdc12b8cb4b9
- https://git.kernel.org/stable/c/59b3732f95dda1fbd2234514d35f4fb6b5bb6d85
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.