CVE-2026-43499

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems: 1) the rbtree dequeue happens without waiter::task::pi_lock being held 2) the waiter task's pi_blocked_on state is not cleared, which leaves a dangling pointer primed for UAF around. 3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the changelog ]
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

24 Jul 2026, 15:17

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/838ce5cb5d93c3ab8b27e75bc6ad905a94b752fd -
  • () https://git.kernel.org/stable/c/f3fa3424bceb128d2be4b3745506b22844b87db7 -

23 Jul 2026, 16:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: rtmutex: Usar waiter::task en lugar de current en remove_waiter() remove_waiter() es usado por las rutas de slowlock, pero también es usado para la reversión de bloqueo de proxy en rt_mutex_start_proxy_lock() cuando es invocado desde futex_requeue(). En este último caso, waiter::task no es current, pero remove_waiter() opera en current para la operación de desencolado. Eso resulta en varios problemas: 1) el desencolado de rbtree ocurre sin que waiter::task::pi_lock esté retenido 2) el estado pi_blocked_on de la tarea de espera no se borra, lo que deja un puntero colgante preparado para UAF. 3) rt_mutex_adjust_prio_chain() opera en la tarea de espera de máxima prioridad incorrecta Usar waiter::task en lugar de current en todas las operaciones relacionadas en remove_waiter() para solucionar esos problemas. [ tglx: Corregir rt_mutex_adjust_prio_chain(), añadir un comentario y modificar el registro de cambios ]

08 Jul 2026, 23:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/07/08/12 -

26 Jun 2026, 17:28

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE CWE-416
References () https://git.kernel.org/stable/c/3bfdc63936dd4773109b7b8c280c0f3b5ae7d349 - () https://git.kernel.org/stable/c/3bfdc63936dd4773109b7b8c280c0f3b5ae7d349 - Patch
References () https://git.kernel.org/stable/c/3fb7394a837740770f0d6b4b30567e60786a63f2 - () https://git.kernel.org/stable/c/3fb7394a837740770f0d6b4b30567e60786a63f2 - Patch
References () https://git.kernel.org/stable/c/6d52dfcb2a5db86e346cf51f8fcf2071b8085166 - () https://git.kernel.org/stable/c/6d52dfcb2a5db86e346cf51f8fcf2071b8085166 - Patch
References () https://git.kernel.org/stable/c/88614876370aac8ad1050ad785a4c095ba17ac11 - () https://git.kernel.org/stable/c/88614876370aac8ad1050ad785a4c095ba17ac11 - Patch
References () https://git.kernel.org/stable/c/8a1fc8d698ac5e5916e3082a0f74450d71f9611f - () https://git.kernel.org/stable/c/8a1fc8d698ac5e5916e3082a0f74450d71f9611f - Patch
References () https://git.kernel.org/stable/c/d8cce4773c2b23d819baf5abedc62f7b430e8745 - () https://git.kernel.org/stable/c/d8cce4773c2b23d819baf5abedc62f7b430e8745 - Patch

01 Jun 2026, 17:17

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/d8cce4773c2b23d819baf5abedc62f7b430e8745 -

30 May 2026, 11:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

21 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 13:16

Updated : 2026-07-24 15:17


NVD link : CVE-2026-43499

Mitre link : CVE-2026-43499

CVE.ORG link : CVE-2026-43499


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-416

Use After Free