« Volver al listado

CVE-2026-80776

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

futex: Fix race in futex_pivot_pending() during private hash resize

A task performing a custom private hash resize can remain blocked in uninterruptible sleep indefinitely. The hung-task detector reports:

futex_pivot_pending() allows the resize request to continue when either no replacement hash is pending (hash_new == NULL) or the current hash reference count has reached zero.

After the final-reference wake, another futex task can complete the pivot between the two observations:

The pivot changes the state from hash_new != NULL with a dead current hash to hash_new == NULL with a live current hash.

Leer descripción completaMostrar menos

Because futex_pivot_pending() reads hash_new and hash without serialization, the resize task can observe hash_new in the pre-pivot state and hash in the post-pivot state, causing futex_pivot_pending() to return false even though the pivot has completed. The task then goes to sleep after the wakeup has already been consumed.

Serialize state reads in futex_pivot_pending() using futex_mm_phash::lock. This guarantees that futex_pivot_pending() observes hash_new and hash atomically, eliminating the race condition.

Detalles técnicos trazas, registros y código del informe original
  INFO: task futex-resizer:314 blocked for more than 10 seconds.
  task:futex-resizer state:D stack:14824 pid:314 tgid:312 ppid:311

  Call Trace:
   __schedule+0x521/0xf30
   schedule+0x22/0xa0
   futex_hash_allocate+0x3db/0x490
   __do_sys_prctl+0x6f5/0xbd0
   do_syscall_64+0xf9/0x530
   entry_SYSCALL_64_after_hwframe+0x77/0x7f

  Kernel panic - not syncing: hung_task: blocked tasks

  T1                                  T2

  futex_hash_allocate()
    wait_var_event(mm, ...)
      futex_pivot_pending(mm)
        hash_new != NULL
                                      futex_hash()
                                        futex_ref_get(old) -> false
                                        futex_pivot_hash(mm)
                                          hash_new = NULL
                                          __futex_pivot_hash(mm, new)
                                            rcu_assign_pointer(hash, new)
        fph = rcu_dereference(hash) /* new */
        futex_ref_is_dead(fph) -> false
      schedule()

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80776",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "bd54df5ea7cadac520e346d5f0fe5d58e635b6ba",
              "lessThan": "4a7e941ca29a608c6244cbd028d3599ecaef7207",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bd54df5ea7cadac520e346d5f0fe5d58e635b6ba",
              "lessThan": "19b4be0717fa83265d66aea836b7022d898422cf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bd54df5ea7cadac520e346d5f0fe5d58e635b6ba",
              "lessThan": "8e7ff730dd96519a333d1570edf1c3fabb6d3629",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/futex/core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.46",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/futex/core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:03.250",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/19b4be0717fa83265d66aea836b7022d898422cf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4a7e941ca29a608c6244cbd028d3599ecaef7207",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8e7ff730dd96519a333d1570edf1c3fabb6d3629",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfutex: Fix race in futex_pivot_pending() during private hash resize\n\nA task performing a custom private hash resize can remain blocked in\nuninterruptible sleep indefinitely.  The hung-task detector reports:\n\n  INFO: task futex-resizer:314 blocked for more than 10 seconds.\n  task:futex-resizer state:D stack:14824 pid:314 tgid:312 ppid:311\n\n  Call Trace:\n   __schedule+0x521/0xf30\n   schedule+0x22/0xa0\n   futex_hash_allocate+0x3db/0x490\n   __do_sys_prctl+0x6f5/0xbd0\n   do_syscall_64+0xf9/0x530\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n  Kernel panic - not syncing: hung_task: blocked tasks\n\nfutex_pivot_pending() allows the resize request to continue when\neither no replacement hash is pending (hash_new == NULL) or the current\nhash reference count has reached zero.\n\nAfter the final-reference wake, another futex task can complete the\npivot between the two observations:\n\n  T1                                  T2\n\n  futex_hash_allocate()\n    wait_var_event(mm, ...)\n      futex_pivot_pending(mm)\n        hash_new != NULL\n                                      futex_hash()\n                                        futex_ref_get(old) -> false\n                                        futex_pivot_hash(mm)\n                                          hash_new = NULL\n                                          __futex_pivot_hash(mm, new)\n                                            rcu_assign_pointer(hash, new)\n        fph = rcu_dereference(hash) /* new */\n        futex_ref_is_dead(fph) -> false\n      schedule()\n\nThe pivot changes the state from hash_new != NULL with a dead current\nhash to hash_new == NULL with a live current hash.  Because\nfutex_pivot_pending() reads hash_new and hash without serialization,\nthe resize task can observe hash_new in the pre-pivot state and hash in\nthe post-pivot state, causing futex_pivot_pending() to return false even\nthough the pivot has completed.  The task then goes to sleep after the\nwakeup has already been consumed.\n\nSerialize state reads in futex_pivot_pending() using futex_mm_phash::lock.\nThis guarantees that futex_pivot_pending() observes hash_new and hash\natomically, eliminating the race condition."
    }
  ],
  "lastModified": "2026-09-04T16:18:03.250",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}