Executive brief
A vulnerability was identified in the Linux kernel's real-time mutex (rtmutex) implementation. This component manages how different tasks wait for access to shared resources. An error in how the system handles task removal during specific locking operations could lead to system instability or a 'use-after-free' scenario, potentially allowing a local attacker to crash the system or execute unauthorized actions.
Technical details
A vulnerability exists in the Linux kernel's rtmutex implementation within `kernel/locking/rtmutex.c`. The `remove_waiter()` function, used during slowlock paths and proxy-lock rollbacks (specifically via `futex_requeue()`), incorrectly operated on the `current` task instead of the actual `waiter->task`. This mismatch resulted in three primary issues: the rbtree dequeue occurred without holding the correct `pi_lock`, the task's `pi_blocked_on` state was not cleared (leaving a dangling pointer), and priority adjustment operated on the wrong task. These conditions create a Use-After-Free (UAF) risk. The fix ensures `waiter->task` is used for all dequeue and priority adjustment operations.
Affected products
- Linux Linux kernel All versions prior to the fix in 2026-05-21 stable releases
Timeline
- 2026-05-21: disclosed
- 2026-05-21: patched
References
- https://git.kernel.org/stable/c/3bfdc63936dd4773109b7b8c280c0f3b5ae7d349
- https://git.kernel.org/stable/c/3fb7394a837740770f0d6b4b30567e60786a63f2
- https://git.kernel.org/stable/c/6d52dfcb2a5db86e346cf51f8fcf2071b8085166
- https://git.kernel.org/stable/c/88614876370aac8ad1050ad785a4c095ba17ac11
- https://git.kernel.org/stable/c/8a1fc8d698ac5e5916e3082a0f74450d71f9611f