CVE-2026-98260
In the Linux kernel, the following vulnerability has been resolved:
exec: Cleanup POSIX timers right after de_thread()
A per-thread CPU timer holds a reference to the PID of the thread it is attached to and, while it is armed, its node is queued in that thread's posix_cputimers. The task is looked up by that PID.
When a non-leader thread exec()s, de_thread() changes which task owns that PID. pid_task(timer->it.cpu.pid, PIDTYPE_PID) then returns NULL, but the node is still queued on tsk, which is alive. timer_lock_sighand() takes a failed lookup to mean that the node is already dequeued, so it has nothing to undo.
Leer descripción completaMostrar menos
begin_new_exec() calls posix_cpu_timers_exit(me) right after exec_task_namespaces() and that removes the leftover node, so the state normally stays invisible. But bprm->point_of_no_return is set before de_thread(), so if unshare_files(), set_mm_exe_file(), exec_mmap() or exec_task_namespaces() fails, the task dies before it gets there. exit_itimers() then frees the k_itimer while its node is still queued, and reaping tsk later erases that freed node from the rbtree.
In short:
Move the POSIX timer cleanup right after de_thread() before any of the later failure conditions brings the task into do_exit().
[ tglx: Move the cleanup right after de_thread() ]
Detalles técnicos trazas, registros y código del informe original
the non-leader thread B the parent
timer_create(CLOCK_THREAD_CPUTIME_ID)
timer_settime()
arm_timer() // the node is queued on B
execve()
de_thread(B)
exchange_tids(B, leader) // B's PID now belongs to the leader
release_task(leader)
__exit_signal(leader)
posix_cpu_timers_exit(leader) // cleans leader's queue, not B's
__unhash_process(leader) // that PID has no task anymore
exec_mmap()
mmap_read_lock_killable(old_mm)
kill(B, SIGKILL)
// -EINTR
get_signal()
do_exit()
exit_itimers()
posix_timer_delete()
posix_cpu_timer_del()
posix_timer_unhash_and_free() // freed while still queued
wait4()
release_task(B)
posix_cpu_timers_exit(B)
cleanup_timerqueue()
timerqueue_del() // use-after-freeCVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/6f1977cea3e85cd8ab55fb337d3e1725fe61d1ce
- https://git.kernel.org/stable/c/75aa08b93c65766040f9ca99f41ac85ad22596b6
- https://git.kernel.org/stable/c/acb03d3881818581052924a9bbbe92b8741ed448
- https://git.kernel.org/stable/c/d602877baf36c43c788a5f472c977e0be414029f
- https://git.kernel.org/stable/c/d9ae467e617ca29b825493a362bf0d75ad5f4ac3
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98260",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "55e8c8eb2c7b6bf30e99423ccfe7ca032f498f59",
"lessThan": "6f1977cea3e85cd8ab55fb337d3e1725fe61d1ce",
"versionType": "git"
},
{
"status": "affected",
"version": "55e8c8eb2c7b6bf30e99423ccfe7ca032f498f59",
"lessThan": "d9ae467e617ca29b825493a362bf0d75ad5f4ac3",
"versionType": "git"
},
{
"status": "affected",
"version": "55e8c8eb2c7b6bf30e99423ccfe7ca032f498f59",
"lessThan": "75aa08b93c65766040f9ca99f41ac85ad22596b6",
"versionType": "git"
},
{
"status": "affected",
"version": "55e8c8eb2c7b6bf30e99423ccfe7ca032f498f59",
"lessThan": "d602877baf36c43c788a5f472c977e0be414029f",
"versionType": "git"
},
{
"status": "affected",
"version": "55e8c8eb2c7b6bf30e99423ccfe7ca032f498f59",
"lessThan": "acb03d3881818581052924a9bbbe92b8741ed448",
"versionType": "git"
}
],
"programFiles": [
"fs/exec.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/exec.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:15.040",
"references": [
{
"url": "https://git.kernel.org/stable/c/6f1977cea3e85cd8ab55fb337d3e1725fe61d1ce",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/75aa08b93c65766040f9ca99f41ac85ad22596b6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/acb03d3881818581052924a9bbbe92b8741ed448",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d602877baf36c43c788a5f472c977e0be414029f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d9ae467e617ca29b825493a362bf0d75ad5f4ac3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nexec: Cleanup POSIX timers right after de_thread()\n\nA per-thread CPU timer holds a reference to the PID of the thread it is\nattached to and, while it is armed, its node is queued in that thread's\nposix_cputimers. The task is looked up by that PID.\n\nWhen a non-leader thread exec()s, de_thread() changes which task owns\nthat PID. pid_task(timer->it.cpu.pid, PIDTYPE_PID) then returns NULL,\nbut the node is still queued on tsk, which is alive. timer_lock_sighand()\ntakes a failed lookup to mean that the node is already dequeued, so it\nhas nothing to undo.\n\nbegin_new_exec() calls posix_cpu_timers_exit(me) right after\nexec_task_namespaces() and that removes the leftover node, so the state\nnormally stays invisible. But bprm->point_of_no_return is set before\nde_thread(), so if unshare_files(), set_mm_exe_file(), exec_mmap() or\nexec_task_namespaces() fails, the task dies before it gets there.\nexit_itimers() then frees the k_itimer while its node is still queued,\nand reaping tsk later erases that freed node from the rbtree.\n\nIn short:\n\n the non-leader thread B the parent\n\n timer_create(CLOCK_THREAD_CPUTIME_ID)\n timer_settime()\n arm_timer() // the node is queued on B\n execve()\n de_thread(B)\n exchange_tids(B, leader) // B's PID now belongs to the leader\n release_task(leader)\n __exit_signal(leader)\n posix_cpu_timers_exit(leader) // cleans leader's queue, not B's\n __unhash_process(leader) // that PID has no task anymore\n exec_mmap()\n mmap_read_lock_killable(old_mm)\n kill(B, SIGKILL)\n // -EINTR\n get_signal()\n do_exit()\n exit_itimers()\n posix_timer_delete()\n posix_cpu_timer_del()\n posix_timer_unhash_and_free() // freed while still queued\n wait4()\n release_task(B)\n posix_cpu_timers_exit(B)\n cleanup_timerqueue()\n timerqueue_del() // use-after-free\n\nMove the POSIX timer cleanup right after de_thread() before any of the\nlater failure conditions brings the task into do_exit().\n\n[ tglx: Move the cleanup right after de_thread() ]"
}
],
"lastModified": "2026-10-06T09:18:15.040",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}