In the Linux kernel, the following vulnerability has been resolved:
futex/pi: Plug private futex exec() race
The check for private futexes whether the waiter's mm, which is stored in the futex_key and copied into the pi_state, is the same as the owner's mm is not sufficient for exec(). exec() has a gap where the mm check fails to give the correct answer:
exec() ... exec_release_mm() futex_exec_release() tsk::futex::exit_state = EXITING; cleanup_robust_list();
tsk::futex::exit_state = OK;
...
old_mm = tsk::mm;Between #1 and #2 the check for the mm is wrong as that mm is about to be swapped out and eventually freed.
Plug this gap by:
Setting tsk::futex::exit_state to FUTEX_STATE_DEAD in futex_exec_release()
Setting tsk::futex::exit_state to FUTEX_STATE_OK after the mm has been switched.
From a futex point of view the task is dead after it finished the robust list cleanup up to the point where it sets the state to OK again.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80777.json"
}