* CVE-2026-80777: futex/pi: Plug private futex exec() race
@ 2026-09-04 15:11 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-04 15:11 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
futex/pi: Plug private futex exec() race
The check for private futexes whether the waiter's mm, which is stored in
the futex_key and copied into the pi_state, is the same as the owner's mm
is not sufficient for exec(). exec() has a gap where the mm check fails to
give the correct answer:
exec()
...
exec_release_mm()
futex_exec_release()
tsk::futex::exit_state = EXITING;
cleanup_robust_list();
1) tsk::futex::exit_state = OK;
...
old_mm = tsk::mm;
2) tsk::mm = ->mm;
Between #1 and #2 the check for the mm is wrong as that mm is about to be
swapped out and eventually freed.
Plug this gap by:
1) Setting tsk::futex::exit_state to FUTEX_STATE_DEAD in
futex_exec_release()
2) Setting tsk::futex::exit_state to FUTEX_STATE_OK after
the mm has been switched.
>From a futex point of view the task is dead after it finished the robust
list cleanup up to the point where it sets the state to OK again.
The Linux kernel CVE team has assigned CVE-2026-80777 to this issue.
Affected and fixed versions
===========================
Issue introduced in 6.16 with commit 80367ad01d93ac781b0e1df246edaf006928002f and fixed in 6.18.47 with commit fdf538b2e69653ff740e84042245018e5680cd7b
Issue introduced in 6.16 with commit 80367ad01d93ac781b0e1df246edaf006928002f and fixed in 7.1.11 with commit 0478bc6bf197629fea0331d65b39eeea043c6cf0
Issue introduced in 6.16 with commit 80367ad01d93ac781b0e1df246edaf006928002f and fixed in 7.2.1 with commit d7944cee62ec6cca1c90780a766960a57d3b4bb8
Issue introduced in 6.16 with commit 80367ad01d93ac781b0e1df246edaf006928002f and fixed in 7.3-rc1 with commit c5f0bc9fd1cec4a00400cc727fcde03e0fde17cc
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-80777
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
fs/exec.c
include/linux/futex.h
kernel/futex/core.c
kernel/futex/pi.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/fdf538b2e69653ff740e84042245018e5680cd7b
https://git.kernel.org/stable/c/0478bc6bf197629fea0331d65b39eeea043c6cf0
https://git.kernel.org/stable/c/d7944cee62ec6cca1c90780a766960a57d3b4bb8
https://git.kernel.org/stable/c/c5f0bc9fd1cec4a00400cc727fcde03e0fde17cc
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-04 15:14 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 15:11 CVE-2026-80777: futex/pi: Plug private futex exec() race Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.