Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix use-after-free on mm_struct in bpf_find_vma()

bpf_find_vma() reads task->mm and calls mmap_read_trylock(mm) without
holding a reference on the mm. On a foreign task, a concurrent exit_mm()
can free the mm_struct between the lockless read and the trylock,
resulting in a use-after-free. mm_struct is not SLAB_TYPESAFE_BY_RCU.

For the current task, task->mm is stable. For a foreign task, pin the mm
under task->alloc_lock and release it with mmput_async(), mirroring commit
d8e27d2d22b6 ("bpf: fix mm lifecycle in open-coded task_vma iterator").
Use spin_trylock() instead of get_task_mm() so BPF context does not block
on alloc_lock. Reject irqs-disabled contexts and !CONFIG_MMU on the
foreign-task path because dropping the mm reference is not safe there.

Race:

CPU0 (BPF program) CPU1 (exiting task)
============================ ==========================
bpf_find_vma(foreign_task):
mm = task->mm
exit_mm():
task->mm = NULL
mmput(mm) -> frees mm_struct
mmap_read_trylock(mm)
// UAF on mm
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free
Action: Patch Now
AI Analysis

Impact

In the Linux kernel, a use-after-free condition exists in the bpf_find_vma() function. When the function accesses a foreign task’s mm_struct without holding a reference, a concurrent task exit can free the mm_struct between the lockless read and the subsequent mmap_read_trylock call. This can lead to memory corruption or a kernel crash if the freed mm_struct is later accessed.

Affected Systems

All Linux kernel releases prior to the patch that implements commit 2b2a903bee56d312539046d9defa8023eec94760. The vulnerability is located in the bpf subsystem and affects any kernel that allows BPF programs to query foreign task VMAs.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, signifying a low probability of exploitation. The likely attack vector is a local kernel attacker who can load a malicious BPF program and target a foreign task that is concurrently exiting – this is an inference based on the described race condition and the need for precise timing between the BPF call and task exit.

Generated by OpenCVE AI on September 20, 2026 at 01:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version containing commit 2b2a903bee56d312539046d9defa8023eec94760 or later, which removes the use-after-free in bpf_find_vma().
  • If an upgrade cannot be applied immediately, consider restricting BPF program execution or limiting access to foreign task memory using seccomp or LSM policies to reduce the window of exploitation.
  • Monitor system logs for kernel crashes or mm_struct-related faults; prompt investigation and patching when such events occur.

Generated by OpenCVE AI on September 20, 2026 at 01:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free on mm_struct in bpf_find_vma() bpf_find_vma() reads task->mm and calls mmap_read_trylock(mm) without holding a reference on the mm. On a foreign task, a concurrent exit_mm() can free the mm_struct between the lockless read and the trylock, resulting in a use-after-free. mm_struct is not SLAB_TYPESAFE_BY_RCU. For the current task, task->mm is stable. For a foreign task, pin the mm under task->alloc_lock and release it with mmput_async(), mirroring commit d8e27d2d22b6 ("bpf: fix mm lifecycle in open-coded task_vma iterator"). Use spin_trylock() instead of get_task_mm() so BPF context does not block on alloc_lock. Reject irqs-disabled contexts and !CONFIG_MMU on the foreign-task path because dropping the mm reference is not safe there. Race: CPU0 (BPF program) CPU1 (exiting task) ============================ ========================== bpf_find_vma(foreign_task): mm = task->mm exit_mm(): task->mm = NULL mmput(mm) -> frees mm_struct mmap_read_trylock(mm) // UAF on mm
Title bpf: Fix use-after-free on mm_struct in bpf_find_vma()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:08.618Z

Reserved: 2026-09-17T16:02:15.088Z

Link: CVE-2026-93137

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:08.600

Modified: 2026-09-18T18:18:22.207

Link: CVE-2026-93137

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:30:16Z

Weaknesses