Executive brief
The Linux kernel's liveupdate subsystem contains a time-of-check-time-of-use (TOCTOU) race condition in session retrieval. A concurrent thread can release and free a session between the time it is looked up and when it is locked, potentially causing use-after-free memory corruption or crashes in systems using live kernel update functionality.
Technical details
This is a classic TOCTOU race condition in the luo_session_retrieve() function within kernel/liveupdate/luo_session.c. The vulnerable code performs a session lookup under a read lock, releases that lock, and then attempts to acquire a session mutex, creating a window where another thread can free the session. The fix extends the scope of the rwsem_read lock to persist through the mutex acquisition, preventing the session from being freed between lookup and lock. The vulnerability was introduced in commit 0153094d03df and is addressed by expanding the guard scope. While the reported severity is low (info), TOCTOU races in kernel memory management can lead to denial of service or potential privilege escalation depending on the session's role.
Affected products
- Linux Linux kernel Versions affected by commit 0153094d03df onwards; patched in 6.14.y and stable backports
Timeline
- 2026-08-15: disclosed: Published on NVD
- 2026-05-27: patched: Upstream fix committed
- 2026-06-01: patched: Merged into main Linux tree
- 2026-07-24: patched: Backported to stable releases