Executive brief
A vulnerability was identified in the Linux kernel's BPF subsystem, which is used for running custom programs within the operating system for monitoring and networking. A flaw in how the system tracks memory associated with running tasks could allow the kernel to access memory that has already been freed, potentially leading to a system crash or unstable behavior. This issue occurs specifically when the system is inspecting the memory mappings of a task that is simultaneously exiting.
Technical details
A use-after-free vulnerability exists in the Linux kernel's BPF subsystem within the open-coded task_vma iterator. The iterator was reading 'task->mm' locklessly and acquiring 'mmap_read_trylock()' without calling 'mmget()' to increment the reference count. Consequently, if the task exits concurrently, the 'mm_struct' can be freed while the iterator is still using it. The fix involves safely reading 'task->mm' using a trylock on 'alloc_lock', acquiring a proper 'mm' reference, and ensuring references are dropped via 'bpf_iter_mmput_async()'. Additionally, the fix rejects IRQ-disabled contexts (including NMI) to prevent potential deadlocks during iteration.
Affected products
- Linux Linux 6.7 to 6.12.90, 6.18.32, 7.0.9
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory