CVE-2026-97617 PUBLISHED

ring-buffer: Check resize_disabled before publishing the new subbuf order

Assigner: Linux
Reserved: 24.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Check resize_disabled before publishing the new subbuf order

ring_buffer_subbuf_order_set() stores the new order and only then walks the CPUs, returning -EBUSY if any of them has resizing disabled. A user mapped buffer has resizing disabled, and __rb_map_vma() reads buffer->subbuf_order without buffer->mutex, so an mmap of an already mapped CPU racing the failing order change sizes the mapping with the new order and inserts pages past the sub-buffer into the VMA.

Check the CPUs before storing the new order.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 117c39200d9d760cbd5944bb89efb7b9c51965aa to f2099644e1b2a2c0805c5240d63ab0522d9d0174 (excl.)
  • affected from 117c39200d9d760cbd5944bb89efb7b9c51965aa to 9fd4ea952e6ac12a63c3fe89f08ad02771aa2c06 (excl.)
  • affected from 117c39200d9d760cbd5944bb89efb7b9c51965aa to 32bf47db9237c5b8b6f6aaa5356bb4c79d241f76 (excl.)
  • affected from 117c39200d9d760cbd5944bb89efb7b9c51965aa to d860c67c051685abb0460b593b193f0f45f4fa92 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.10 is affected
  • unaffected from 0 to 6.10 (excl.)
  • unaffected from 6.12.111 to 6.12.* (incl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc3 to * (incl.)

References