-

CVE-2026-80777

futex/pi: Plug private futex exec() race

In the Linux kernel, the following vulnerability has been resolved:

futex/pi: Plug private futex exec() race

The check for private futexes whether the waiter's mm, which is stored in
the futex_key and copied into the pi_state, is the same as the owner's mm
is not sufficient for exec(). exec() has a gap where the mm check fails to
give the correct answer:

  exec()
  ...
    exec_release_mm()
      futex_exec_release()
        tsk::futex::exit_state = EXITING;
        cleanup_robust_list();
1)      tsk::futex::exit_state = OK;
    ...
    old_mm = tsk::mm;
2)  tsk::mm = ->mm;

Between #1 and #2 the check for the mm is wrong as that mm is about to be
swapped out and eventually freed.

Plug this gap by:

  1) Setting tsk::futex::exit_state to FUTEX_STATE_DEAD in
     futex_exec_release()

  2) Setting tsk::futex::exit_state to FUTEX_STATE_OK after
     the mm has been switched.

From a futex point of view the task is dead after it finished the robust
list cleanup up to the point where it sets the state to OK again.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 80367ad01d93ac781b0e1df246edaf006928002f
Version < fdf538b2e69653ff740e84042245018e5680cd7b
Status affected
Version 80367ad01d93ac781b0e1df246edaf006928002f
Version < 0478bc6bf197629fea0331d65b39eeea043c6cf0
Status affected
Version 80367ad01d93ac781b0e1df246edaf006928002f
Version < d7944cee62ec6cca1c90780a766960a57d3b4bb8
Status affected
Version 80367ad01d93ac781b0e1df246edaf006928002f
Version < c5f0bc9fd1cec4a00400cc727fcde03e0fde17cc
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.16
Status affected
Version 0
Version < 6.16
Status unaffected
Version <= 6.18.*
Version 6.18.47
Status unaffected
Version <= 7.1.*
Version 7.1.11
Status unaffected
Version <= 7.2.*
Version 7.2.1
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/fdf538b2e69653ff740e84042245018e5680cd7b
https://git.kernel.org/stable/c/0478bc6bf197629fea0331d65b39eeea043c6cf0
https://git.kernel.org/stable/c/d7944cee62ec6cca1c90780a766960a57d3b4bb8
https://git.kernel.org/stable/c/c5f0bc9fd1cec4a00400cc727fcde03e0fde17cc