Junglewise Threat Intelligence

CVE-2026-98163: Linux kernel cgroup iterator use-after-free with dying tasks

CVE-2026-98163 · Severity: info · Published 2026-09-26

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's cgroup subsystem has a race condition when iterating through task lists that can lead to a use-after-free vulnerability. An attacker with local access could exploit this to crash the system or potentially execute arbitrary code by referencing a task structure after it has been freed from memory.

Technical details

A race condition exists in css_task_iter_next() between the point where a task's usage count drops to zero and when it is removed from the dying_tasks list. The iterator does not check the task's usage count before calling get_task_struct(), allowing it to increment the reference count on a task that is already scheduled for deallocation via RCU callbacks. This leads to a classic use-after-free where the iterator returns a dangling pointer to freed task_struct memory.

Affected products

  • Linux Linux kernel affected versions prior to the fix

Timeline

  • 2026-09-26: disclosed

Related threats