Executive brief
A deadlock vulnerability exists in the Linux kernel's BPF (Berkeley Packet Filter) arena memory management subsystem. When the kernel attempts to deallocate memory pages in certain concurrent scenarios, it can cause a system hang that requires a restart, disrupting production services and availability.
Technical details
The vulnerability is a deadlock (AB-BA lock ordering) in the kernel/bpf/arena.c zap_pages() function. The function previously attempted to take mmap_read_lock() while holding arena->lock; however, other code paths (arena_vm_close() and arena_map_mmap()) acquire mmap_write_lock first and then arena->lock, creating a deadlock cycle. The fix involves dropping arena->lock before acquiring mmap_read_lock, then re-resolving the vma via find_vma() and introducing a per-call generation counter (vml->zap_gen) plus a new arena->zap_mutex to serialize concurrent callers and prevent race conditions. This is a kernel-level issue affecting the BPF subsystem with no network or local privilege escalation requirements—impact is localized to system stability when concurrent BPF arena operations occur.
Affected products
- Linux Linux kernel 5.8 and later (before fix in upstream)
Timeline
- 2026-05-28: disclosed: Vulnerability reported by David Hildenbrand
- 2026-06-04: patched: Fix merged into Linux mainline (commit 80b89d0226a05e8b67969de99c31b51fcd54f76a)
- 2026-08-15: advisory: CVE-2026-74354 published