futex/pi: Plug private futex exec() race
Summary
| CVE | CVE-2026-80777 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-04 16:18:03 UTC |
| Updated | 2026-09-04 16:18:03 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
futex/pi: Plug private futex exec() race
The check for private futexes whether the waiter's mm, which is stored in
the futex_key and copied into the pi_state, is the same as the owner's mm
is not sufficient for exec(). exec() has a gap where the mm check fails to
give the correct answer:
exec()
...
exec_release_mm()
futex_exec_release()
tsk::futex::exit_state = EXITING;
cleanup_robust_list();
1) tsk::futex::exit_state = OK;
...
old_mm = tsk::mm;
2) tsk::mm = ->mm;
Between #1 and #2 the check for the mm is wrong as that mm is about to be
swapped out and eventually freed.
Plug this gap by:
1) Setting tsk::futex::exit_state to FUTEX_STATE_DEAD in
futex_exec_release()
2) Setting tsk::futex::exit_state to FUTEX_STATE_OK after
the mm has been switched.
From a futex point of view the task is dead after it finished the robust
list cleanup up to the point where it sets the state to OK again. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 80367ad01d93ac781b0e1df246edaf006928002f fdf538b2e69653ff740e84042245018e5680cd7b git |
Not specified |
| CNA |
Linux |
Linux |
affected 80367ad01d93ac781b0e1df246edaf006928002f 0478bc6bf197629fea0331d65b39eeea043c6cf0 git |
Not specified |
| CNA |
Linux |
Linux |
affected 80367ad01d93ac781b0e1df246edaf006928002f d7944cee62ec6cca1c90780a766960a57d3b4bb8 git |
Not specified |
| CNA |
Linux |
Linux |
affected 80367ad01d93ac781b0e1df246edaf006928002f c5f0bc9fd1cec4a00400cc727fcde03e0fde17cc git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.16 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.16 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.47 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.11 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.1 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/c5f0bc9fd1cec4a00400cc727fcde03e0fde17cc |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/d7944cee62ec6cca1c90780a766960a57d3b4bb8 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0478bc6bf197629fea0331d65b39eeea043c6cf0 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/fdf538b2e69653ff740e84042245018e5680cd7b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.