CVE-2026-97617
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
ring-buffer: Check resize_disabled before publishing the new subbuf order
ring_buffer_subbuf_order_set() stores the new order and only then walks the CPUs, returning -EBUSY if any of them has resizing disabled. A user mapped buffer has resizing disabled, and __rb_map_vma() reads buffer->subbuf_order without buffer->mutex, so an mmap of an already mapped CPU racing the failing order change sizes the mapping with the new order and inserts pages past the sub-buffer into the VMA.
Check the CPUs before storing the new order.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 117c39200d9d760cbd5944bb89efb7b9c51965aa < f2099644e1b2a2c0805c5240d63ab0522d9d0174 | affected |
| Linux | Linux | 117c39200d9d760cbd5944bb89efb7b9c51965aa < 9fd4ea952e6ac12a63c3fe89f08ad02771aa2c06 | affected |
| Linux | Linux | 117c39200d9d760cbd5944bb89efb7b9c51965aa < 32bf47db9237c5b8b6f6aaa5356bb4c79d241f76 | affected |
| Linux | Linux | 117c39200d9d760cbd5944bb89efb7b9c51965aa < d860c67c051685abb0460b593b193f0f45f4fa92 | affected |
| Linux | Linux | 6.10 | affected |
| Linux | Linux | 0 < 6.10 | unaffected |
| Linux | Linux | 6.12.111 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc3 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/f2099644e1b2a2c0805c5240d63ab0522d9d0174
- https://git.kernel.org/stable/c/9fd4ea952e6ac12a63c3fe89f08ad02771aa2c06
- https://git.kernel.org/stable/c/32bf47db9237c5b8b6f6aaa5356bb4c79d241f76
- https://git.kernel.org/stable/c/d860c67c051685abb0460b593b193f0f45f4fa92
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.