๐Ÿ” CVE Alert

CVE-2026-90003

UNKNOWN 0.0

futex: Prevent rcuwait use-after-free during requeue PI

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: futex: Prevent rcuwait use-after-free during requeue PI On PREEMPT_RT, FUTEX_CMP_REQUEUE_PI can trigger a KASAN report (slab-out-of-bounds) in futex_requeue_pi_complete() invocation of rcuwait_wake_up(). The futex_q used by futex_wait_requeue_pi() is allocated on the waiter's stack. An early wakeup can race with a PI requeue as follows: waiter requeue task ------ ------------ futex_wait_requeue_pi() futex_do_wait() schedule() futex_requeue futex_proxy_trylock_atomic() futex_requeue_pi_prepare() Q_REQUEUE_PI_NONE -> Q_REQUEUE_PI_IN_PROGRESS * timeout/ signal wakes waiter * futex_requeue_pi_wakeup_sync() Q_REQUEUE_PI_IN_PROGRESS -> Q_REQUEUE_PI_WAIT requeue_pi_wake_futex futex_requeue_pi_complete() cmpxchg Q_REQUEUE_PI_WAIT -> Q_REQUEUE_PI_LOCKED rcuwait_wait_event() if (atomic_read(&q->requeue_state) != Q_REQUEUE_PI_WAIT) break /* no schedule() */ /* q.pi_state->owner == current */ futex_private_hash_put() /* return from syscall */ rcuwait_wake_up(&q->requeue_wait) /* q is gone */ futex_requeue_pi_complete() publishes Q_REQUEUE_PI_LOCKED before calling rcuwait_wake_up(). The waiter observes this state in rcuwait_wait_event() before invoking schedule() in rcuwait_wait_event(). Here, the waiter is free leave the syscall before requeue task can complete the wake. To address this race skip rcuwait_wake_up() in the Q_REQUEUE_PI_LOCKED case. This state is only published by requeue_pi_wake_futex(), which saves q->task before futex_requeue_pi_complete() and wakes the waiter via wake_up_state(). This wake is intended to wake the waiter from its futex_do_wait() sleep. If the waiter is still sleeping there, it can not get into the Q_REQUEUE_PI_WAIT state (and require this removed wake). Should the waiter be woken up from futex_do_wait() by other means (as in this example) and sleep in futex_requeue_pi_wakeup_sync() then the wake_up_state() from requeue_pi_wake_futex() will wake it, too. Should the waiter task terminate before wake_up_state() had a chance to wake the task then the task pointer does not become invalid because the futex_hash_bucket::lock is held and the task pointer is RCU protected. [bigeasy: Updated comment and commit message]

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
07d91ef510fb16a2e0ca7453222105835b7ba3b8 < 220ee9e04ca3b7f014c000264aa6c884f036c86e 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < 81aadbd09bf1dcd3238212f336ba699503557ae8 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < 244f301759fd34b1dd0b4192ce44f8ef224e027d 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < 7d1559126d86be6e4f6a85663dfbfe85caa47e37 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < e4a4ccfa470f910b747b3ee8d18670ed8ac8a236 07d91ef510fb16a2e0ca7453222105835b7ba3b8 < a3b8d46fe401cba3a5c46dea610e6eb3dc15370e
Linux / Linux
5.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/220ee9e04ca3b7f014c000264aa6c884f036c86e git.kernel.org: https://git.kernel.org/stable/c/81aadbd09bf1dcd3238212f336ba699503557ae8 git.kernel.org: https://git.kernel.org/stable/c/244f301759fd34b1dd0b4192ce44f8ef224e027d git.kernel.org: https://git.kernel.org/stable/c/7d1559126d86be6e4f6a85663dfbfe85caa47e37 git.kernel.org: https://git.kernel.org/stable/c/e4a4ccfa470f910b747b3ee8d18670ed8ac8a236 git.kernel.org: https://git.kernel.org/stable/c/a3b8d46fe401cba3a5c46dea610e6eb3dc15370e