Executive brief
The Linux kernel's cgroup subsystem has a race condition when iterating through task lists that can lead to a use-after-free vulnerability. An attacker with local access could exploit this to crash the system or potentially execute arbitrary code by referencing a task structure after it has been freed from memory.
Technical details
A race condition exists in css_task_iter_next() between the point where a task's usage count drops to zero and when it is removed from the dying_tasks list. The iterator does not check the task's usage count before calling get_task_struct(), allowing it to increment the reference count on a task that is already scheduled for deallocation via RCU callbacks. This leads to a classic use-after-free where the iterator returns a dangling pointer to freed task_struct memory.
Affected products
- Linux Linux kernel affected versions prior to the fix
Timeline
- 2026-09-26: disclosed