CVE-2026-90003
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
futex: Prevent rcuwait use-after-free during requeue PI
On PREEMPT_RT, FUTEX_CMP_REQUEUE_PI can trigger a KASAN report (slab-out-of-bounds) in futex_requeue_pi_complete() invocation of rcuwait_wake_up().
The futex_q used by futex_wait_requeue_pi() is allocated on the waiter's stack. An early wakeup can race with a PI requeue as follows:
waiter requeue task
------ ------------
futex_wait_requeue_pi() futex_do_wait() schedule() futex_requeue futex_proxy_trylock_atomic() futex_requeue_pi_prepare() Q_REQUEUE_PI_NONE -> Q_REQUEUE_PI_IN_PROGRESS
- timeout/ signal wakes waiter * futex_requeue_pi_wakeup_sync() Q_REQUEUE_PI_IN_PROGRESS -> Q_REQUEUE_PI_WAIT requeue_pi_wake_futex futex_requeue_pi_complete() cmpxchg Q_REQUEUE_PI_WAIT -> Q_REQUEUE_PI_LOCKED rcuwait_wait_event() if (atomic_read(&q->requeue_state) != Q_REQUEUE_PI_WAIT) break /* no schedule() */
/* q.pi_state->owner == current / futex_private_hash_put() / return from syscall / rcuwait_wake_up(&q->requeue_wait) / q is gone */
futex_requeue_pi_complete() publishes Q_REQUEUE_PI_LOCKED before calling rcuwait_wake_up(). The waiter observes this state in rcuwait_wait_event() before invoking schedule() in rcuwait_wait_event(). Here, the waiter is free leave the syscall before requeue task can complete the wake.
To address this race skip rcuwait_wake_up() in the Q_REQUEUE_PI_LOCKED case. This state is only published by requeue_pi_wake_futex(), which saves q->task before futex_requeue_pi_complete() and wakes the waiter via wake_up_state().
This wake is intended to wake the waiter from its futex_do_wait() sleep. If the waiter is still sleeping there, it can not get into the Q_REQUEUE_PI_WAIT state (and require this removed wake). Should the waiter be woken up from futex_do_wait() by other means (as in this example) and sleep in futex_requeue_pi_wakeup_sync() then the wake_up_state() from requeue_pi_wake_futex() will wake it, too. Should the waiter task terminate before wake_up_state() had a chance to wake the task then the task pointer does not become invalid because the futex_hash_bucket::lock is held and the task pointer is RCU protected.
[bigeasy: Updated comment and commit message]
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < 220ee9e04ca3b7f014c000264aa6c884f036c86e | affected |
| Linux | Linux | 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < 81aadbd09bf1dcd3238212f336ba699503557ae8 | affected |
| Linux | Linux | 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < 244f301759fd34b1dd0b4192ce44f8ef224e027d | affected |
| Linux | Linux | 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < 7d1559126d86be6e4f6a85663dfbfe85caa47e37 | affected |
| Linux | Linux | 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < e4a4ccfa470f910b747b3ee8d18670ed8ac8a236 | affected |
| Linux | Linux | 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < a3b8d46fe401cba3a5c46dea610e6eb3dc15370e | affected |
| Linux | Linux | 5.15 | affected |
| Linux | Linux | 0 < 5.15 | unaffected |
| Linux | Linux | 6.1.188 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.157 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.51 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.5 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/220ee9e04ca3b7f014c000264aa6c884f036c86e
- https://git.kernel.org/stable/c/81aadbd09bf1dcd3238212f336ba699503557ae8
- https://git.kernel.org/stable/c/244f301759fd34b1dd0b4192ce44f8ef224e027d
- https://git.kernel.org/stable/c/7d1559126d86be6e4f6a85663dfbfe85caa47e37
- https://git.kernel.org/stable/c/e4a4ccfa470f910b747b3ee8d18670ed8ac8a236
- https://git.kernel.org/stable/c/a3b8d46fe401cba3a5c46dea610e6eb3dc15370e
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.