From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 236074F0548 for ; Fri, 4 Sep 2026 15:14:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788534889; cv=none; b=Ocqq/c1bcY14lsCHGkFUOdGCihfOnWESXSERBqV9ucgKbrg/wFWoci7AI5+bdUQUU7iwq2XJg4NDymnidX9Gf9NCTdQ46tCDx71Q5PqcxU0A/mG+CD5iRsDMikTTEnnO/rg8MKguRA8hO3+fiVEdq2zDpcyGvOcmhHN//0QWDe4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788534889; c=relaxed/simple; bh=hhoItVrAeGYyFoy0Xa34d1mH7CEX2yoaspLqKhXPWT0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=GFAJlILghRe8UkotUM/mQijSz3Jh4G1ZR7VCRmL7wfJRhIdMlbEg0k1D9JV8EGh1lwFti8O0vM6DKu6kMOuQmwTV/BRStfyBnZVb+wZGTKOzrfwTbNbNWYT05V3pKdMhI6768To41/TCqKfd4QywNT6DEaEp/ldPXdkN/nsP8io= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=AGCDg+LY; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="AGCDg+LY" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 9C8D91F00A3D; Fri, 4 Sep 2026 15:14:45 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788534887; bh=IPydCj7F1LWww6KOeHJTzXT74juhw6NHEm1gDxMlAe0=; h=From:To:Cc:Subject:Date:Reply-To; b=AGCDg+LYAs5vCrN3W61mNnAVgEwbBNiBGTjeJ/6cimjo/Rz2EEI6vms6fVqO3UOGs Pkq8x9kFQTJsNFgg7VGzVMvOMHPCGUmzoNiGF2f/uFYf6ZKWV+Ap9tlum++Eu+UrQb Hqr/khLjK0uOnF57oX8/n4nvgnXIhQHSQ9Qg8OW0= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80777: futex/pi: Plug private futex exec() race Date: Fri, 4 Sep 2026 17:11:16 +0200 Message-ID: <2026090403-CVE-2026-80777-6065@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3205; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=hXY37mqBtYxbCHFfbr1+fQDCwSbD44guQcKJb0TLjhA=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmz7revFWbftvO91aHQoI3H529cKOgodvLecZPy3rQdH 63evT91piOWhUGQiUFWTJHlyzaeo/srDil6GdqehpnDygQyhIGLUwAm8iOeYcGe13z2vtf1tcRz Oc/XyX2ZeSz3jD/D/Hj2h+5vdl51XyBaceaP5CqtvxpvsgE= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: futex/pi: Plug private futex exec() race The check for private futexes whether the waiter's mm, which is stored in the futex_key and copied into the pi_state, is the same as the owner's mm is not sufficient for exec(). exec() has a gap where the mm check fails to give the correct answer: exec() ... exec_release_mm() futex_exec_release() tsk::futex::exit_state = EXITING; cleanup_robust_list(); 1) tsk::futex::exit_state = OK; ... old_mm = tsk::mm; 2) tsk::mm = ->mm; Between #1 and #2 the check for the mm is wrong as that mm is about to be swapped out and eventually freed. Plug this gap by: 1) Setting tsk::futex::exit_state to FUTEX_STATE_DEAD in futex_exec_release() 2) Setting tsk::futex::exit_state to FUTEX_STATE_OK after the mm has been switched. >>From a futex point of view the task is dead after it finished the robust list cleanup up to the point where it sets the state to OK again. The Linux kernel CVE team has assigned CVE-2026-80777 to this issue. Affected and fixed versions =========================== Issue introduced in 6.16 with commit 80367ad01d93ac781b0e1df246edaf006928002f and fixed in 6.18.47 with commit fdf538b2e69653ff740e84042245018e5680cd7b Issue introduced in 6.16 with commit 80367ad01d93ac781b0e1df246edaf006928002f and fixed in 7.1.11 with commit 0478bc6bf197629fea0331d65b39eeea043c6cf0 Issue introduced in 6.16 with commit 80367ad01d93ac781b0e1df246edaf006928002f and fixed in 7.2.1 with commit d7944cee62ec6cca1c90780a766960a57d3b4bb8 Issue introduced in 6.16 with commit 80367ad01d93ac781b0e1df246edaf006928002f and fixed in 7.3-rc1 with commit c5f0bc9fd1cec4a00400cc727fcde03e0fde17cc Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80777 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/exec.c include/linux/futex.h kernel/futex/core.c kernel/futex/pi.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/fdf538b2e69653ff740e84042245018e5680cd7b https://git.kernel.org/stable/c/0478bc6bf197629fea0331d65b39eeea043c6cf0 https://git.kernel.org/stable/c/d7944cee62ec6cca1c90780a766960a57d3b4bb8 https://git.kernel.org/stable/c/c5f0bc9fd1cec4a00400cc727fcde03e0fde17cc