Executive brief
The Linux kernel's BPF (Berkeley Packet Filter) subsystem contains a use-after-free vulnerability in the bpf_find_vma() function that can be triggered when BPF programs inspect memory maps of other processes. An attacker with BPF capabilities can cause the kernel to access freed memory by timing a race condition with process exit, potentially leading to kernel crashes or code execution with kernel privileges.
Technical details
The vulnerability is a use-after-free race condition in the bpf_find_vma() helper function (kernel/bpf/task_iter.c). The function reads task→mm from a foreign (non-current) task and calls mmap_read_trylock(mm) without holding a reference on the mm_struct. A concurrent exit_mm() from the target task can free the mm_struct between the lockless read and the trylock attempt, causing the function to dereference freed memory. The fix implements proper reference counting: for foreign tasks, the mm is pinned under task→alloc_lock using mmget(), then released with mmput_async(), while rejecting unsafe contexts (IRQs disabled, !CONFIG_MMU). The vulnerability requires CAP_PERFMON or CAP_SYS_ADMIN to load BPF programs and local code execution. A patch is available in upstream kernel commit 47b079e2117a2ee52e21f8b72935900c702fc0b5.
Affected products
- Linux Linux kernel 5.7 and later through 6.10+
Timeline
- 2026-09-17: disclosed
- 2026-07-09: patched: Upstream fix committed
- 2026-09-14: other: Backport merged to stable trees