Executive brief
A vulnerability was discovered in the Linux kernel's signal handling mechanism. When a multi-threaded application attempts to replace itself with a new process while simultaneously receiving a stop signal, the system can enter an inconsistent state. This results in a kernel warning and potential instability, though it primarily impacts the reliability of the affected process rather than exposing sensitive data.
Technical details
A race condition exists in the Linux kernel's `zap_other_threads()` function within `kernel/signal.c`. When a multi-threaded process receives a stop signal (e.g., SIGSTOP), the kernel sets `JOBCTL_STOP_PENDING` and `JOBCTL_STOP_CONSUME` flags. If a thread concurrently calls `execve()`, `zap_other_threads()` is invoked to terminate other threads and abort the group stop. However, the function fails to clear the `JOBCTL_PENDING_MASK` for the calling thread. This results in the calling thread retaining stale flags, leading to an invalid attempt to decrement `signal->group_stop_count` (which is already zero) when returning to user mode, triggering a kernel WARNING. The fix involves ensuring `JOBCTL_PENDING_MASK` is cleared for the caller in `zap_other_threads()`.
Affected products
- Linux Linux Kernel 39efa3ef3a37 and later
Timeline
- 2026-05-21: other: Patch submitted by Aleksandr Nogikh
- 2026-06-19: patched: Commits merged into stable branches
- 2026-07-01: disclosed: CVE published
References
- https://git.kernel.org/stable/c/2b32b2fb241435145ea199efac024540759d2495
- https://git.kernel.org/stable/c/391ebe74456a0f1d60b3ba4a8a64d9f44c1728fe
- https://git.kernel.org/stable/c/76aebd9ef20078719dfd6282d3b06c27e900a65a
- https://git.kernel.org/stable/c/8c046f36222c6ce1e0daef2c45c891c72602f8a1
- https://git.kernel.org/stable/c/90918794a4e2c3b440f8fcf3847765a8b1d81b25
- https://git.kernel.org/stable/c/dfcd0ba14769d94d76ac9d9814b85e7fcacd4e29
- https://git.kernel.org/stable/c/f4aae11abb449dc536269705d0419ec69480faa9