CVE-2026-80778 PUBLISHED

futex/pi: Reject cross-mm private futex owners

Assigner: Linux
Reserved: 26.08.2026 Published: 04.09.2026 Updated: 04.09.2026

In the Linux kernel, the following vulnerability has been resolved:

futex/pi: Reject cross-mm private futex owners

A private futex key borrows the waiter's mm without taking an mm_users reference. Nevertheless, attach_to_pi_owner() currently accepts an owner from a different address space and copies the private key into the owner's PI state.

When that owner exits, exit_pi_state_list() uses the saved key to find the hash bucket and acquires a reference to the waiter's private hash. If the last user of the waiter's mm exits concurrently, futex_hash_free() frees the hash while the owner still uses its bucket and reference.

Prevent this by validating in attach_to_pi_owner() that, for private futexes, the owner mm and waiter mm are the same. Perform the check with the owner's pi_lock held and after validating owner::futex::state to serialize against a concurrent PI-state exit cleanup.

[ tglx: Amended comment ]

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 80367ad01d93ac781b0e1df246edaf006928002f to 2b92e5562653b5293529f63b0300837d9dcedbd7 (excl.)
  • affected from 80367ad01d93ac781b0e1df246edaf006928002f to f7fb3e07752688842cbe0b85cf0d98c2fbf76b68 (excl.)
  • affected from 80367ad01d93ac781b0e1df246edaf006928002f to 43b148d796aa338858792d0167cebdc12b8cb4b9 (excl.)
  • affected from 80367ad01d93ac781b0e1df246edaf006928002f to 59b3732f95dda1fbd2234514d35f4fb6b5bb6d85 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.16 is affected
  • unaffected from 0 to 6.16 (excl.)
  • unaffected from 6.18.47 to 6.18.* (incl.)
  • unaffected from 7.1.11 to 7.1.* (incl.)
  • unaffected from 7.2.1 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References