Impact
A race condition exists in the Linux kernel’s futex requeue mechanism for Priority Inheritance (PI), specifically under the PREEMPT_RT kernel configuration. When a waiting task is woken prematurely while a requeue operation is in progress, the code may access memory for a futex queue that has already been freed. This triggers a KASAN slab‑out‑of‑bounds report and can corrupt kernel memory or cause a crash. The immediate impact is a denial of service or kernel panic, as the corrupted memory can lead to undefined behavior when used later in kernel execution. The vulnerability is a classic use‑after‑free and does not provide direct arbitrary code execution, but the extent of memory corruption could enable advanced attacks if an attacker can control the affected memory.
Affected Systems
All Linux distributions that use the standard Linux kernel compiled with the PREEMPT_RT patch set are potentially vulnerable. The affected code resides in the futex subsystem and applies to any kernel that lacks the fused patch fixing the rcuwait_wake_up logic. Versions older than the commit that introduced the mitigation are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity vulnerability that can lead to system instability. The EPSS score of less than 1% indicates a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, suggesting no large‑scale public exploitation. Attack execution requires local access with the ability to trigger the specific racing condition between a waiting task and a requeue task, thus it is categorized as a local kernel exploitation scenario rather than a remote, publicly exploitable flaw.
OpenCVE Enrichment
Debian DLA
Debian DSA