7.8

CVE-2026-93137

bpf: Fix use-after-free on mm_struct in bpf_find_vma()

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix use-after-free on mm_struct in bpf_find_vma()

bpf_find_vma() reads task->mm and calls mmap_read_trylock(mm) without
holding a reference on the mm. On a foreign task, a concurrent exit_mm()
can free the mm_struct between the lockless read and the trylock,
resulting in a use-after-free. mm_struct is not SLAB_TYPESAFE_BY_RCU.

For the current task, task->mm is stable. For a foreign task, pin the mm
under task->alloc_lock and release it with mmput_async(), mirroring commit
d8e27d2d22b6 ("bpf: fix mm lifecycle in open-coded task_vma iterator").
Use spin_trylock() instead of get_task_mm() so BPF context does not block
on alloc_lock. Reject irqs-disabled contexts and !CONFIG_MMU on the
foreign-task path because dropping the mm reference is not safe there.

Race:

  CPU0 (BPF program)                  CPU1 (exiting task)
  ============================        ==========================
  bpf_find_vma(foreign_task):
    mm = task->mm
                                      exit_mm():
                                        task->mm = NULL
                                        mmput(mm) -> frees mm_struct
    mmap_read_trylock(mm)
        // UAF on mm
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 7c7e3d31e7856a8260a254f8c71db416f7f9f5a1
Version < db347840d6b6ee9bb9b8e4a985d4b4419f9f3200
Status affected
Version 7c7e3d31e7856a8260a254f8c71db416f7f9f5a1
Version < 8e1101fc4118019a69c96ced4aec93164f89cbd5
Status affected
Version 7c7e3d31e7856a8260a254f8c71db416f7f9f5a1
Version < c7ad910e987008e125eeff448892e86852173384
Status affected
Version 7c7e3d31e7856a8260a254f8c71db416f7f9f5a1
Version < 86d54cf069fc5ae2e111c87933bebf6eb527978e
Status affected
Version 7c7e3d31e7856a8260a254f8c71db416f7f9f5a1
Version < 2b2a903bee56d312539046d9defa8023eec94760
Status affected
Version 7c7e3d31e7856a8260a254f8c71db416f7f9f5a1
Version < 47b079e2117a2ee52e21f8b72935900c702fc0b5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.17
Status affected
Version 0
Version < 5.17
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.055
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/db347840d6b6ee9bb9b8e4a985d4b4419f9f3200
https://git.kernel.org/stable/c/8e1101fc4118019a69c96ced4aec93164f89cbd5
https://git.kernel.org/stable/c/c7ad910e987008e125eeff448892e86852173384
https://git.kernel.org/stable/c/86d54cf069fc5ae2e111c87933bebf6eb527978e
https://git.kernel.org/stable/c/2b2a903bee56d312539046d9defa8023eec94760
https://git.kernel.org/stable/c/47b079e2117a2ee52e21f8b72935900c702fc0b5