๐Ÿ” CVE Alert

CVE-2026-53163

UNKNOWN 0.0

locking/rtmutex: Skip remove_waiter() when waiter is not enqueued

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued syzbot triggered the following splat in remove_waiter() via FUTEX_CMP_REQUEUE_PI: KASAN: null-ptr-deref in range [0x0000000000000a88-0x0000000000000a8f] class_raw_spinlock_constructor remove_waiter+0x159/0x1200 kernel/locking/rtmutex.c:1561 rt_mutex_start_proxy_lock+0x103/0x120 futex_requeue+0x10e4/0x20d0 __x64_sys_futex+0x34f/0x4d0 task_blocks_on_rt_mutex() does not arm the waiter upon deadlock detection, leaving waiter->task nil, where 3bfdc63936dd ("rtmutex: Use waiter::task instead of current in remove_waiter()") made this fatal. Furthermore, rt_mutex_start_proxy_lock() should not be calling into remove_waiter() upon a successfully grabbing the rtmutex. 1a1fb985f2e2 ("futex: Handle early deadlock return correctly"), moved the remove_waiter() out of __rt_mutex_start_proxy_lock() (where 'ret' was only ever 0 or < 0) into the wrapper. Tighten this check to account for try_to_take_rt_mutex().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jun 25, 2026
Last Updated Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
f3fa3424bceb128d2be4b3745506b22844b87db7 < bfbc047ceb42c0e1fac8f3a155d4548a8bbe76b1 838ce5cb5d93c3ab8b27e75bc6ad905a94b752fd < 4ffacf76a457b7ca8ac05f5df8740b0d8f53574a d8cce4773c2b23d819baf5abedc62f7b430e8745 < 4afda3a1da02129568a3a2f1898aa13e6763bcba 8a1fc8d698ac5e5916e3082a0f74450d71f9611f < 6707d7e0b71748cb3cd95bad81dae5fe1b3c8f48 6d52dfcb2a5db86e346cf51f8fcf2071b8085166 < 5799f9bd7fee40370b93ab1ddf001cdc7017c14d 3fb7394a837740770f0d6b4b30567e60786a63f2 < a388e3dfaf9538a680de5ed43a8ebb5dd45b6e53 88614876370aac8ad1050ad785a4c095ba17ac11 < 55363fa0a04524d11efeaadee734d2db1756ed27 3bfdc63936dd4773109b7b8c280c0f3b5ae7d349 < 40a25d59e85b3c8709ac2424d44f65610467871e
Linux / Linux
6.1.175 < 6.1.177 6.6.140 < 6.6.144 6.12.86 < 6.12.95 6.18.27 < 6.18.36 7.0.4 < 7.0.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/bfbc047ceb42c0e1fac8f3a155d4548a8bbe76b1 git.kernel.org: https://git.kernel.org/stable/c/4ffacf76a457b7ca8ac05f5df8740b0d8f53574a git.kernel.org: https://git.kernel.org/stable/c/4afda3a1da02129568a3a2f1898aa13e6763bcba git.kernel.org: https://git.kernel.org/stable/c/6707d7e0b71748cb3cd95bad81dae5fe1b3c8f48 git.kernel.org: https://git.kernel.org/stable/c/5799f9bd7fee40370b93ab1ddf001cdc7017c14d git.kernel.org: https://git.kernel.org/stable/c/a388e3dfaf9538a680de5ed43a8ebb5dd45b6e53 git.kernel.org: https://git.kernel.org/stable/c/55363fa0a04524d11efeaadee734d2db1756ed27 git.kernel.org: https://git.kernel.org/stable/c/40a25d59e85b3c8709ac2424d44f65610467871e