Description
In the Linux kernel, the following vulnerability has been resolved:

futex/pi: Plug private futex exec() race

The check for private futexes whether the waiter's mm, which is stored in
the futex_key and copied into the pi_state, is the same as the owner's mm
is not sufficient for exec(). exec() has a gap where the mm check fails to
give the correct answer:

exec()
...
exec_release_mm()
futex_exec_release()
tsk::futex::exit_state = EXITING;
cleanup_robust_list();
1) tsk::futex::exit_state = OK;
...
old_mm = tsk::mm;
2) tsk::mm = ->mm;

Between #1 and #2 the check for the mm is wrong as that mm is about to be
swapped out and eventually freed.

Plug this gap by:

1) Setting tsk::futex::exit_state to FUTEX_STATE_DEAD in
futex_exec_release()

2) Setting tsk::futex::exit_state to FUTEX_STATE_OK after
the mm has been switched.

From a futex point of view the task is dead after it finished the robust
list cleanup up to the point where it sets the state to OK again.
Published: 2026-09-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The kernel flaw is a race condition in the private futex subsystem that arises during an exec transition. While the exec process is swapping in a new mm structure, the futex check for ownership still references the old mm, allowing a malicious process to override or corrupt the futex state. This can lead to a use‑after‑free or arbitrary code execution in kernel mode, effectively permitting privilege escalation. The weakness is a classic race condition (CWE‑362) with possible use‑after‑free behavior (CWE‑416).

Affected Systems

All Linux kernel releases that run the vulnerable code path are affected. The CVE does not list specific version ranges, so any kernel that has not yet incorporated the patch is at risk. Distributions that ship a patched kernel or an up‑to‑date kernel package, or containers that use a recent base image, are not impacted once they have applied the fix.

Risk and Exploitability

The exploit requires a local attacker who can schedule the race during an exec transition. No EPSS score is currently available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not widely exploited yet. However, the severity of a kernel use‑after‑free or arbitrary code execution remains high, and the lack of a public exploitation metric means defensive action should be treated with caution. The CVSS score is not provided, but the fundamental nature of the bug indicates a high inherent risk for affected systems.

Generated by OpenCVE AI on September 4, 2026 at 17:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update your kernel to the patched version that includes the fix for the futex/pi exec race.
  • If a patch is not available for your environment, consider restricting the use of private futexes for untrusted processes or disabling robust futex support where possible.
  • Continuously monitor kernel logs (e.g., dmesg, /var/log/kern.log) for unusual futex‑related errors or process kills to detect potential exploitation attempts.

Generated by OpenCVE AI on September 4, 2026 at 17:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: futex/pi: Plug private futex exec() race The check for private futexes whether the waiter's mm, which is stored in the futex_key and copied into the pi_state, is the same as the owner's mm is not sufficient for exec(). exec() has a gap where the mm check fails to give the correct answer: exec() ... exec_release_mm() futex_exec_release() tsk::futex::exit_state = EXITING; cleanup_robust_list(); 1) tsk::futex::exit_state = OK; ... old_mm = tsk::mm; 2) tsk::mm = ->mm; Between #1 and #2 the check for the mm is wrong as that mm is about to be swapped out and eventually freed. Plug this gap by: 1) Setting tsk::futex::exit_state to FUTEX_STATE_DEAD in futex_exec_release() 2) Setting tsk::futex::exit_state to FUTEX_STATE_OK after the mm has been switched. From a futex point of view the task is dead after it finished the robust list cleanup up to the point where it sets the state to OK again.
Title futex/pi: Plug private futex exec() race
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-04T15:12:49.215Z

Reserved: 2026-08-26T14:34:25.792Z

Link: CVE-2026-80777

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T16:18:03.373

Modified: 2026-09-04T16:18:03.373

Link: CVE-2026-80777

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T17:30:17Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free