Junglewise Threat Intelligence

CVE-2026-53085: Linux Kernel use-after-free in BPF task_vma iterator

CVE-2026-53085 · Severity: info · Published 2026-06-24

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's BPF subsystem, which is used for running custom programs within the operating system for monitoring and networking. A flaw in how the system tracks memory associated with running tasks could allow the kernel to access memory that has already been freed, potentially leading to a system crash or unstable behavior. This issue occurs specifically when the system is inspecting the memory mappings of a task that is simultaneously exiting.

Technical details

A use-after-free vulnerability exists in the Linux kernel's BPF subsystem within the open-coded task_vma iterator. The iterator was reading 'task->mm' locklessly and acquiring 'mmap_read_trylock()' without calling 'mmget()' to increment the reference count. Consequently, if the task exits concurrently, the 'mm_struct' can be freed while the iterator is still using it. The fix involves safely reading 'task->mm' using a trylock on 'alloc_lock', acquiring a proper 'mm' reference, and ensuring references are dropped via 'bpf_iter_mmput_async()'. Additionally, the fix rejects IRQ-disabled contexts (including NMI) to prevent potential deadlocks during iteration.

Affected products

  • Linux Linux 6.7 to 6.12.90, 6.18.32, 7.0.9

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory

References