CVE-2026-98258
In the Linux kernel, the following vulnerability has been resolved:
posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
Kijo analyzed another race in the POSIX CPU timer code:
Commit bf635681c906 converted cpu_timer::firing from a tristate value to a boolean. This lost the distinction between "not owned by the firing list" and "still owned, but delivery was canceled". The resulting race is:
The firing bit is clearly the wrong indicator since that commit.
Check whether the timer is queued on the expiry list or not instead. If it is queued clear the firing bit to prevent signal delivery as before and return TIMER_RETRY so the caller unlocks the timer which allows the expiry code to make progress and remove it from the list.
Detalles técnicos trazas, registros y código del informe original
expiry handler timer_settime() timer_delete()
-------------- --------------- --------------
collect timer onto
private firing list
firing = true
observes firing = true
firing = false
return TIMER_RETRY
wait for handler
observes firing = false
finish deletion
unhash and free timer
resume list traversal
read freed elist.next
-> UAFCVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98258",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "bf635681c906ad056d1fda325de8d1c12c9f8201",
"lessThan": "9971dac1a77845ff467146915fcbb9170f6a8209",
"versionType": "git"
},
{
"status": "affected",
"version": "bf635681c906ad056d1fda325de8d1c12c9f8201",
"lessThan": "4336e3f47d9d516441066e9a65eaf076790d8d45",
"versionType": "git"
},
{
"status": "affected",
"version": "bf635681c906ad056d1fda325de8d1c12c9f8201",
"lessThan": "c21eaa72f02fc6e85621cbe09d303d8fb8bd39cd",
"versionType": "git"
}
],
"programFiles": [
"kernel/time/posix-cpu-timers.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"kernel/time/posix-cpu-timers.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:14.737",
"references": [
{
"url": "https://git.kernel.org/stable/c/4336e3f47d9d516441066e9a65eaf076790d8d45",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9971dac1a77845ff467146915fcbb9170f6a8209",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c21eaa72f02fc6e85621cbe09d303d8fb8bd39cd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nposix-cpu-timers: Prevent freeing a timer which is queued on the expiry list\n\nKijo analyzed another race in the POSIX CPU timer code:\n\nCommit bf635681c906 converted cpu_timer::firing from a tristate value to a\nboolean. This lost the distinction between \"not owned by the firing list\"\nand \"still owned, but delivery was canceled\". The resulting race is:\n\n expiry handler timer_settime() timer_delete()\n -------------- --------------- --------------\n collect timer onto\n private firing list\n firing = true\n observes firing = true\n firing = false\n return TIMER_RETRY\n wait for handler\n observes firing = false\n finish deletion\n unhash and free timer\n resume list traversal\n read freed elist.next\n -> UAF\n\nThe firing bit is clearly the wrong indicator since that commit.\n\nCheck whether the timer is queued on the expiry list or not instead. If it\nis queued clear the firing bit to prevent signal delivery as before and\nreturn TIMER_RETRY so the caller unlocks the timer which allows the expiry\ncode to make progress and remove it from the list."
}
],
"lastModified": "2026-10-06T09:18:14.737",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}