Executive brief
A vulnerability in the Linux kernel's x86 shadow stack implementation could allow a local attacker to cause a system crash or denial of service. Shadow stacks are a security feature designed to prevent certain types of memory attacks; however, a flaw in how the kernel handles memory locking during signal processing can lead to unstable behavior. This issue primarily impacts system availability.
Technical details
A vulnerability exists in the x86 shadow stack implementation within the Linux kernel due to improper error handling of the mmap lock. Specifically, the function 'shstk_pop_sigframe()' fails to check the return value of 'mmap_read_lock_killable()'. If the lock acquisition is interrupted (e.g., by a signal), the function continues execution without holding the necessary lock, leading to potential kernel instability or a crash. The fix involves adding proper return value checks in 'shstk_pop_sigframe()' and marking mmap lock functions with '__must_check' to prevent similar oversights in the future. This is a local vulnerability requiring low privileges.
Affected products
- Linux Linux Kernel 6.6 to 6.18.24, 6.19 to 6.19.14, 7.0-rc1 to 7.0-rc7
Timeline
- 2026-04-08: patched: Initial patch by Linus Torvalds
- 2026-05-06: disclosed: CVE published
- 2026-05-11: advisory: NVD enrichment and analysis
References
- https://git.kernel.org/stable/c/1a30468eff661937d978495644d2e5ebfeef5ce6
- https://git.kernel.org/stable/c/262b6d38a81d51b135db81e1f30c13d30e38feee
- https://git.kernel.org/stable/c/52f657e34d7b21b47434d9d8b26fa7f6778b63a0
- https://git.kernel.org/stable/c/c64cebcc5c4f223dbcbe7dcdf74908fc092a0aa4
- https://git.kernel.org/stable/c/c79cf42321600e931933e11f94aba8b245d4cd66