CVE-2026-31555
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/04/2026
Last modified:
27/04/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
futex: Clear stale exiting pointer in futex_lock_pi() retry path<br />
<br />
Fuzzying/stressing futexes triggered:<br />
<br />
WARNING: kernel/futex/core.c:825 at wait_for_owner_exiting+0x7a/0x80, CPU#11: futex_lock_pi_s/524<br />
<br />
When futex_lock_pi_atomic() sees the owner is exiting, it returns -EBUSY<br />
and stores a refcounted task pointer in &#39;exiting&#39;.<br />
<br />
After wait_for_owner_exiting() consumes that reference, the local pointer<br />
is never reset to nil. Upon a retry, if futex_lock_pi_atomic() returns a<br />
different error, the bogus pointer is passed to wait_for_owner_exiting().<br />
<br />
CPU0 CPU1 CPU2<br />
futex_lock_pi(uaddr)<br />
// acquires the PI futex<br />
exit()<br />
futex_cleanup_begin()<br />
futex_state = EXITING;<br />
futex_lock_pi(uaddr)<br />
futex_lock_pi_atomic()<br />
attach_to_pi_owner()<br />
// observes EXITING<br />
*exiting = owner; // takes ref<br />
return -EBUSY<br />
wait_for_owner_exiting(-EBUSY, owner)<br />
put_task_struct(); // drops ref<br />
// exiting still points to owner<br />
goto retry;<br />
futex_lock_pi_atomic()<br />
lock_pi_update_atomic()<br />
cmpxchg(uaddr)<br />
*uaddr ^= WAITERS // whatever<br />
// value changed<br />
return -EAGAIN;<br />
wait_for_owner_exiting(-EAGAIN, exiting) // stale<br />
WARN_ON_ONCE(exiting)<br />
<br />
Fix this by resetting upon retry, essentially aligning it with requeue_pi.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.4.255 (including) | 4.5 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.9.255 (including) | 4.10 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.14.158 (including) | 4.15 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.19.172 (including) | 4.20 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.4.1 (including) | 5.5 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5.1 (including) | 5.10.253 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.203 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.168 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.131 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.80 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.21 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 6.19.11 (excluding) |
| cpe:2.3:o:linux:linux_kernel:5.5:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/210d36d892de5195e6766c45519dfb1e65f3eb83
- https://git.kernel.org/stable/c/33095ae3bdde5e5c264d7e88a2f3e7703a26c7aa
- https://git.kernel.org/stable/c/5e8e06bf8909e79b4acd950cf578cfc2f10bbefa
- https://git.kernel.org/stable/c/71112e62807d1925dc3ae6188b11f8cfc85aec23
- https://git.kernel.org/stable/c/7475dfad10a05a5bfadebf5f2499bd61b19ed293
- https://git.kernel.org/stable/c/92e47ad03e03dbb5515bdf06444bf6b1e147310d
- https://git.kernel.org/stable/c/de7c0c04ad868f2cee6671b11c0a6d20421af1da
- https://git.kernel.org/stable/c/e7824ec168d2ac883a213cd1f4d6cc0816002a85



