In the Linux kernel, the following vulnerability has been resolved:
rtmutex: Use waiter::task instead of current in remove_waiter()
remove_waiter() is used by the slowlock paths, but it is also used for
proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from
futex_requeue().
In the latter case waiter::task is not current, but remove_waiter()
operates on current for the dequeue operation. That results in several
problems:
1) the rbtree dequeue happens without waiter::task::pi_lock being held
2) the waiter task's pi_blocked_on state is not cleared, which leaves a
dangling pointer primed for UAF around.
3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter
task
Use waiter::task instead of current in all related operations in
remove_waiter() to cure those problems.
[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the
changelog ]
References
Configurations
Configuration 1 (hide)
|
History
24 Jul 2026, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
23 Jul 2026, 16:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
08 Jul 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
26 Jun 2026, 17:28
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Linux linux Kernel
Linux |
|
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
| CWE | CWE-416 | |
| References | () https://git.kernel.org/stable/c/3bfdc63936dd4773109b7b8c280c0f3b5ae7d349 - Patch | |
| References | () https://git.kernel.org/stable/c/3fb7394a837740770f0d6b4b30567e60786a63f2 - Patch | |
| References | () https://git.kernel.org/stable/c/6d52dfcb2a5db86e346cf51f8fcf2071b8085166 - Patch | |
| References | () https://git.kernel.org/stable/c/88614876370aac8ad1050ad785a4c095ba17ac11 - Patch | |
| References | () https://git.kernel.org/stable/c/8a1fc8d698ac5e5916e3082a0f74450d71f9611f - Patch | |
| References | () https://git.kernel.org/stable/c/d8cce4773c2b23d819baf5abedc62f7b430e8745 - Patch |
01 Jun 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 May 2026, 11:17
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
21 May 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-21 13:16
Updated : 2026-07-24 15:17
NVD link : CVE-2026-43499
Mitre link : CVE-2026-43499
CVE.ORG link : CVE-2026-43499
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free
