Junglewise Threat Intelligence

CVE-2026-93137: Linux kernel use-after-free in bpf_find_vma()

CVE-2026-93137 · Severity: high · CVSS 7.8 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's BPF (Berkeley Packet Filter) subsystem contains a use-after-free vulnerability in the bpf_find_vma() function that can be triggered when BPF programs inspect memory maps of other processes. An attacker with BPF capabilities can cause the kernel to access freed memory by timing a race condition with process exit, potentially leading to kernel crashes or code execution with kernel privileges.

Technical details

The vulnerability is a use-after-free race condition in the bpf_find_vma() helper function (kernel/bpf/task_iter.c). The function reads task→mm from a foreign (non-current) task and calls mmap_read_trylock(mm) without holding a reference on the mm_struct. A concurrent exit_mm() from the target task can free the mm_struct between the lockless read and the trylock attempt, causing the function to dereference freed memory. The fix implements proper reference counting: for foreign tasks, the mm is pinned under task→alloc_lock using mmget(), then released with mmput_async(), while rejecting unsafe contexts (IRQs disabled, !CONFIG_MMU). The vulnerability requires CAP_PERFMON or CAP_SYS_ADMIN to load BPF programs and local code execution. A patch is available in upstream kernel commit 47b079e2117a2ee52e21f8b72935900c702fc0b5.

Affected products

  • Linux Linux kernel 5.7 and later through 6.10+

Timeline

  • 2026-09-17: disclosed
  • 2026-07-09: patched: Upstream fix committed
  • 2026-09-14: other: Backport merged to stable trees

References

Related threats