Junglewise Threat Intelligence

CVE-2026-52977: Linux Kernel live lock in futex requeue-PI during signal wakeup

CVE-2026-52977 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's synchronization mechanism (futex) can cause the system to freeze or become unresponsive. This occurs when a specific sequence of events involving task timeouts or signals causes the system to enter an infinite loop. This could lead to a complete service outage or system lockup, requiring a hard reboot to recover.

Technical details

A race condition exists in the Linux kernel's futex implementation, specifically within the requeue-PI (Priority Inheritance) logic. When a task (Task A) is woken up early due to a signal or timeout while another task (Task B) is performing a requeue operation, a priority inversion or scheduling conflict can occur. If Task B has a higher priority or is on a uniprocessor (UP) system, it may busy-loop while Task A is blocked on a hash bucket lock held by Task B, resulting in a live lock. The root cause is that Task A cannot remove itself from the waiter list without the lock held by Task B, while Task B will not progress until Task A is removed. The fix involves ensuring the top waiter is removed from the list if preparation fails, allowing the requeue process to continue with the next waiter.

Affected products

  • Linux Linux Kernel 07d91ef510fb1 to 4e0ed44e51727d56244a822ab941efe507c47966

Timeline

  • 2026-04-28: other: Vulnerability fixed in upstream commits
  • 2026-06-24: disclosed: CVE published

References

Related threats