CVE-2026-53163

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
25/06/2026
Last modified:
07/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> locking/rtmutex: Skip remove_waiter() when waiter is not enqueued<br /> <br /> syzbot triggered the following splat in remove_waiter() via<br /> FUTEX_CMP_REQUEUE_PI:<br /> <br /> KASAN: null-ptr-deref in range [0x0000000000000a88-0x0000000000000a8f]<br /> class_raw_spinlock_constructor<br /> remove_waiter+0x159/0x1200 kernel/locking/rtmutex.c:1561<br /> rt_mutex_start_proxy_lock+0x103/0x120<br /> futex_requeue+0x10e4/0x20d0<br /> __x64_sys_futex+0x34f/0x4d0<br /> <br /> task_blocks_on_rt_mutex() does not arm the waiter upon deadlock detection,<br /> leaving waiter-&gt;task nil, where 3bfdc63936dd ("rtmutex: Use waiter::task instead<br /> of current in remove_waiter()") made this fatal.<br /> <br /> Furthermore, rt_mutex_start_proxy_lock() should not be calling into remove_waiter()<br /> upon a successfully grabbing the rtmutex. 1a1fb985f2e2 ("futex: Handle early deadlock<br /> return correctly"), moved the remove_waiter() out of __rt_mutex_start_proxy_lock()<br /> (where &amp;#39;ret&amp;#39; was only ever 0 or

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.1.175 (including) 6.1.177 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.6.140 (including) 6.6.144 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.12.86 (including) 6.12.95 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.18.27 (including) 6.18.36 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 7.0.4 (including) 7.0.13 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*