Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix mmap_lock deadlock on arena lock failure

Reported by the Sashiko AI review.

arena_vm_fault() returns VM_FAULT_RETRY when it can't take
arena->spinlock, but it never took mmap_lock. The fault path assumes a
VM_FAULT_RETRY handler already dropped mmap_lock and re-takes it on the
retry, so mmap_lock gets taken twice and can deadlock:

do_user_addr_fault()
{
fault = handle_mm_fault(...); // calls arena_vm_fault()
if (fault & VM_FAULT_RETRY)
goto retry; // re-locks mmap_lock
mmap_read_unlock(mm);
}

Return VM_FAULT_SIGBUS instead, for two reasons:

1. We could keep VM_FAULT_RETRY, but then we'd have to drop the fault
lock first and cap the retry ourselves, the way __folio_lock_or_retry()
does.

2. A failed raw_res_spin_lock_irqsave() already means a possible deadlock
was detected, so retrying just hits the same lock again.

So returning VM_FAULT_RETRY here is overkill.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Deadlock leading to kernel stall
Action: Patch
AI Analysis

Impact

In the Linux kernel a memory‑fault handling path can acquire the mmap lock twice when a retry is attempted after failing to acquire the arena lock, causing a deadlock. The deadlock may halt kernel activity and result in a denial of service. The flaw occurs during kernel fault handling; it is therefore a low‑level race condition that can be triggered by operations that cause address faults in a bpf program. Based on the description, the likely attack vector is an attacker with the ability to run code in the kernel or to provoke fault conditions from user space, such as a malicious or misbehaving bpf program. The impact is confined to the affected kernel operating system. The vulnerability is cataloged under CWE‑847 (Improper Synchronization).

Affected Systems

Linux kernel products from the mainline Linux distribution are affected. No specific kernel versions are enumerated in the available data, so all releases that include the bpf subsystem are potentially impacted until a patch is applied.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, indicating a low probability of exploitation in the wild. However, because the flaw leads to a kernel deadlock, it can cause a system‑wide denial of service if successfully triggered. The need for privileged code or ability to induce faults means an attacker would need significant access, but once attained the effect is severe.

Generated by OpenCVE AI on September 19, 2026 at 04:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that contains the bpf mmap_lock deadlock fix.
  • Ensure all systems are running a patched kernel version; apply distribution security updates promptly.
  • Audit and monitor for abnormal kernel hangs related to bpf programs, and restrict untrusted bpf programs until the patch is deployed.

Generated by OpenCVE AI on September 19, 2026 at 04:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Fix mmap_lock deadlock on arena lock failure Reported by the Sashiko AI review. arena_vm_fault() returns VM_FAULT_RETRY when it can't take arena->spinlock, but it never took mmap_lock. The fault path assumes a VM_FAULT_RETRY handler already dropped mmap_lock and re-takes it on the retry, so mmap_lock gets taken twice and can deadlock: do_user_addr_fault() { fault = handle_mm_fault(...); // calls arena_vm_fault() if (fault & VM_FAULT_RETRY) goto retry; // re-locks mmap_lock mmap_read_unlock(mm); } Return VM_FAULT_SIGBUS instead, for two reasons: 1. We could keep VM_FAULT_RETRY, but then we'd have to drop the fault lock first and cap the retry ourselves, the way __folio_lock_or_retry() does. 2. A failed raw_res_spin_lock_irqsave() already means a possible deadlock was detected, so retrying just hits the same lock again. So returning VM_FAULT_RETRY here is overkill.
Title bpf: Fix mmap_lock deadlock on arena lock failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:53.010Z

Reserved: 2026-09-11T19:38:34.804Z

Link: CVE-2026-90342

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:32.877

Modified: 2026-09-17T17:17:32.877

Link: CVE-2026-90342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T10:45:06Z

Weaknesses

No weakness.