๐Ÿ” CVE Alert

CVE-2026-93137

UNKNOWN 0.0

bpf: Fix use-after-free on mm_struct in bpf_find_vma()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free on mm_struct in bpf_find_vma() bpf_find_vma() reads task->mm and calls mmap_read_trylock(mm) without holding a reference on the mm. On a foreign task, a concurrent exit_mm() can free the mm_struct between the lockless read and the trylock, resulting in a use-after-free. mm_struct is not SLAB_TYPESAFE_BY_RCU. For the current task, task->mm is stable. For a foreign task, pin the mm under task->alloc_lock and release it with mmput_async(), mirroring commit d8e27d2d22b6 ("bpf: fix mm lifecycle in open-coded task_vma iterator"). Use spin_trylock() instead of get_task_mm() so BPF context does not block on alloc_lock. Reject irqs-disabled contexts and !CONFIG_MMU on the foreign-task path because dropping the mm reference is not safe there. Race: CPU0 (BPF program) CPU1 (exiting task) ============================ ========================== bpf_find_vma(foreign_task): mm = task->mm exit_mm(): task->mm = NULL mmput(mm) -> frees mm_struct mmap_read_trylock(mm) // UAF on mm

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
7c7e3d31e7856a8260a254f8c71db416f7f9f5a1 < db347840d6b6ee9bb9b8e4a985d4b4419f9f3200 7c7e3d31e7856a8260a254f8c71db416f7f9f5a1 < 8e1101fc4118019a69c96ced4aec93164f89cbd5 7c7e3d31e7856a8260a254f8c71db416f7f9f5a1 < c7ad910e987008e125eeff448892e86852173384 7c7e3d31e7856a8260a254f8c71db416f7f9f5a1 < 86d54cf069fc5ae2e111c87933bebf6eb527978e 7c7e3d31e7856a8260a254f8c71db416f7f9f5a1 < 2b2a903bee56d312539046d9defa8023eec94760 7c7e3d31e7856a8260a254f8c71db416f7f9f5a1 < 47b079e2117a2ee52e21f8b72935900c702fc0b5
Linux / Linux
5.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/db347840d6b6ee9bb9b8e4a985d4b4419f9f3200 git.kernel.org: https://git.kernel.org/stable/c/8e1101fc4118019a69c96ced4aec93164f89cbd5 git.kernel.org: https://git.kernel.org/stable/c/c7ad910e987008e125eeff448892e86852173384 git.kernel.org: https://git.kernel.org/stable/c/86d54cf069fc5ae2e111c87933bebf6eb527978e git.kernel.org: https://git.kernel.org/stable/c/2b2a903bee56d312539046d9defa8023eec94760 git.kernel.org: https://git.kernel.org/stable/c/47b079e2117a2ee52e21f8b72935900c702fc0b5