CVE-2026-90003

Summary

In the Linux kernel, the following vulnerability has been resolved:

futex: Prevent rcuwait use-after-free during requeue PI

On PREEMPT_RT, FUTEX_CMP_REQUEUE_PI can trigger a KASAN report (slab-out-of-bounds) in futex_requeue_pi_complete() invocation of rcuwait_wake_up().

The futex_q used by futex_wait_requeue_pi() is allocated on the waiter's stack. An early wakeup can race with a PI requeue as follows:

    waiter                          requeue task
    ------                          ------------

futex_wait_requeue_pi() futex_do_wait() schedule() futex_requeue futex_proxy_trylock_atomic() futex_requeue_pi_prepare() Q_REQUEUE_PI_NONE -> Q_REQUEUE_PI_IN_PROGRESS

  • timeout/ signal wakes waiter * futex_requeue_pi_wakeup_sync() Q_REQUEUE_PI_IN_PROGRESS -> Q_REQUEUE_PI_WAIT requeue_pi_wake_futex futex_requeue_pi_complete() cmpxchg Q_REQUEUE_PI_WAIT -> Q_REQUEUE_PI_LOCKED rcuwait_wait_event() if (atomic_read(&q->requeue_state) != Q_REQUEUE_PI_WAIT) break /* no schedule() */

/* q.pi_state->owner == current / futex_private_hash_put() / return from syscall / rcuwait_wake_up(&q->requeue_wait) / q is gone */

futex_requeue_pi_complete() publishes Q_REQUEUE_PI_LOCKED before calling rcuwait_wake_up(). The waiter observes this state in rcuwait_wait_event() before invoking schedule() in rcuwait_wait_event(). Here, the waiter is free leave the syscall before requeue task can complete the wake.

To address this race skip rcuwait_wake_up() in the Q_REQUEUE_PI_LOCKED case. This state is only published by requeue_pi_wake_futex(), which saves q->task before futex_requeue_pi_complete() and wakes the waiter via wake_up_state().

This wake is intended to wake the waiter from its futex_do_wait() sleep. If the waiter is still sleeping there, it can not get into the Q_REQUEUE_PI_WAIT state (and require this removed wake). Should the waiter be woken up from futex_do_wait() by other means (as in this example) and sleep in futex_requeue_pi_wakeup_sync() then the wake_up_state() from requeue_pi_wake_futex() will wake it, too. Should the waiter task terminate before wake_up_state() had a chance to wake the task then the task pointer does not become invalid because the futex_hash_bucket::lock is held and the task pointer is RCU protected.

[bigeasy: Updated comment and commit message]

Affected Software

VendorProductVersion RangeStatus
LinuxLinux07d91ef510fb16a2e0ca7453222105835b7ba3b8 < 220ee9e04ca3b7f014c000264aa6c884f036c86eaffected
LinuxLinux07d91ef510fb16a2e0ca7453222105835b7ba3b8 < 81aadbd09bf1dcd3238212f336ba699503557ae8affected
LinuxLinux07d91ef510fb16a2e0ca7453222105835b7ba3b8 < 244f301759fd34b1dd0b4192ce44f8ef224e027daffected
LinuxLinux07d91ef510fb16a2e0ca7453222105835b7ba3b8 < 7d1559126d86be6e4f6a85663dfbfe85caa47e37affected
LinuxLinux07d91ef510fb16a2e0ca7453222105835b7ba3b8 < e4a4ccfa470f910b747b3ee8d18670ed8ac8a236affected
LinuxLinux07d91ef510fb16a2e0ca7453222105835b7ba3b8 < a3b8d46fe401cba3a5c46dea610e6eb3dc15370eaffected
LinuxLinux5.15affected
LinuxLinux0 < 5.15unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc2 <= *unaffected

Weaknesses

References