-

CVE-2026-80778

futex/pi: Reject cross-mm private futex owners

In the Linux kernel, the following vulnerability has been resolved:

futex/pi: Reject cross-mm private futex owners

A private futex key borrows the waiter's mm without taking an mm_users
reference. Nevertheless, attach_to_pi_owner() currently accepts an owner
from a different address space and copies the private key into the owner's
PI state.

When that owner exits, exit_pi_state_list() uses the saved key to find the
hash bucket and acquires a reference to the waiter's private hash. If the
last user of the waiter's mm exits concurrently, futex_hash_free() frees
the hash while the owner still uses its bucket and reference.

Prevent this by validating in attach_to_pi_owner() that, for private
futexes, the owner mm and waiter mm are the same. Perform the check with
the owner's pi_lock held and after validating owner::futex::state to
serialize against a concurrent PI-state exit cleanup.

[ tglx: Amended comment ]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 80367ad01d93ac781b0e1df246edaf006928002f
Version < 2b92e5562653b5293529f63b0300837d9dcedbd7
Status affected
Version 80367ad01d93ac781b0e1df246edaf006928002f
Version < f7fb3e07752688842cbe0b85cf0d98c2fbf76b68
Status affected
Version 80367ad01d93ac781b0e1df246edaf006928002f
Version < 43b148d796aa338858792d0167cebdc12b8cb4b9
Status affected
Version 80367ad01d93ac781b0e1df246edaf006928002f
Version < 59b3732f95dda1fbd2234514d35f4fb6b5bb6d85
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.16
Status affected
Version 0
Version < 6.16
Status unaffected
Version <= 6.18.*
Version 6.18.47
Status unaffected
Version <= 7.1.*
Version 7.1.11
Status unaffected
Version <= 7.2.*
Version 7.2.1
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2b92e5562653b5293529f63b0300837d9dcedbd7
https://git.kernel.org/stable/c/f7fb3e07752688842cbe0b85cf0d98c2fbf76b68
https://git.kernel.org/stable/c/43b148d796aa338858792d0167cebdc12b8cb4b9
https://git.kernel.org/stable/c/59b3732f95dda1fbd2234514d35f4fb6b5bb6d85