{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93137","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.088Z","datePublished":"2026-09-17T16:11:38.135Z","dateUpdated":"2026-09-18T17:56:08.618Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:56:08.618Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix use-after-free on mm_struct in bpf_find_vma()\n\nbpf_find_vma() reads task->mm and calls mmap_read_trylock(mm) without\nholding a reference on the mm. On a foreign task, a concurrent exit_mm()\ncan free the mm_struct between the lockless read and the trylock,\nresulting in a use-after-free. mm_struct is not SLAB_TYPESAFE_BY_RCU.\n\nFor the current task, task->mm is stable. For a foreign task, pin the mm\nunder task->alloc_lock and release it with mmput_async(), mirroring commit\nd8e27d2d22b6 (\"bpf: fix mm lifecycle in open-coded task_vma iterator\").\nUse spin_trylock() instead of get_task_mm() so BPF context does not block\non alloc_lock. Reject irqs-disabled contexts and !CONFIG_MMU on the\nforeign-task path because dropping the mm reference is not safe there.\n\nRace:\n\n  CPU0 (BPF program)                  CPU1 (exiting task)\n  ============================        ==========================\n  bpf_find_vma(foreign_task):\n    mm = task->mm\n                                      exit_mm():\n                                        task->mm = NULL\n                                        mmput(mm) -> frees mm_struct\n    mmap_read_trylock(mm)\n        // UAF on mm"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - bpf_find_vma() is invoked only from a program loaded via bpf(BPF_PROG_LOAD): BPF_PROG_TYPE_SYSCALL (syscall_prog_func_proto) or tracing/raw_tp (bpf_tracing_func_proto), both reaching bpf_base_func_proto() for BPF_FUNC_find_vma. The stale mm comes from bpf_task_from_pid() or a tracing task argument, not from a remote protocol field.\nAC:L - The race is inside bpf_find_vma() between the lockless task->mm load and mmap_read_trylock(mm). The attacker forks a child, looks it up with bpf_task_from_pid(), and hammers BPF_PROG_RUN (or an attached raw_tp) while that child exits so exit_mm()→mmput() frees the mm; they control both sides.\nPR:L - bpf_base_func_proto() returns bpf_find_vma_proto only after bpf_token_capable(CAP_PERFMON); bpf_prog_load() also needs CAP_BPF, and RAW_TRACEPOINT/TRACING fail is_perfmon_prog_type() without CAP_PERFMON. bpf_token_capable() uses ns_capable() on a delegated token's userns, so this is not init-namespace root.\nUI:N - The attacker loads the program with BPF_PROG_LOAD, runs it via BPF_PROG_RUN or their own attached probe, and exits their own child so exit_mm() races bpf_find_vma(); no other user must mount a filesystem or open a file.\nS:U - mmap_read_trylock() and find_vma() operate on the host kernel mm_struct that bpf_find_vma() cached from task->mm. That is in-kernel memory corruption in the same authority as the bpf() caller, not a KVM/Xen guest-to-host or IOMMU escape.\nC:H - After exit_mm() mmput() frees the mm_struct (mm_cachep is not SLAB_TYPESAFE_BY_RCU), bpf_find_vma() still calls find_vma(mm, start) and hands the resulting vm_area_struct to the BPF callback, so the program can read reallocated kernel VMA/mm memory.\nI:H - The stale mm is used by mmap_read_trylock() (down_read_trylock on mm->mmap_lock) and bpf_mmap_unlock_mm(); those write a freed mm_struct, and find_vma() may walk a reallocated maple tree, which is UAF corruption exploitable for an arbitrary kernel write.\nA:H - down_read_trylock on a freed mm->mmap_lock or find_vma() walking a freed mm->mm_mt oopses or panics the kernel, and the attacker can repeat bpf_find_vma() against children they exit."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/task_iter.c"],"versions":[{"version":"7c7e3d31e7856a8260a254f8c71db416f7f9f5a1","lessThan":"db347840d6b6ee9bb9b8e4a985d4b4419f9f3200","status":"affected","versionType":"git"},{"version":"7c7e3d31e7856a8260a254f8c71db416f7f9f5a1","lessThan":"8e1101fc4118019a69c96ced4aec93164f89cbd5","status":"affected","versionType":"git"},{"version":"7c7e3d31e7856a8260a254f8c71db416f7f9f5a1","lessThan":"c7ad910e987008e125eeff448892e86852173384","status":"affected","versionType":"git"},{"version":"7c7e3d31e7856a8260a254f8c71db416f7f9f5a1","lessThan":"86d54cf069fc5ae2e111c87933bebf6eb527978e","status":"affected","versionType":"git"},{"version":"7c7e3d31e7856a8260a254f8c71db416f7f9f5a1","lessThan":"2b2a903bee56d312539046d9defa8023eec94760","status":"affected","versionType":"git"},{"version":"7c7e3d31e7856a8260a254f8c71db416f7f9f5a1","lessThan":"47b079e2117a2ee52e21f8b72935900c702fc0b5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/task_iter.c"],"versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/db347840d6b6ee9bb9b8e4a985d4b4419f9f3200"},{"url":"https://git.kernel.org/stable/c/8e1101fc4118019a69c96ced4aec93164f89cbd5"},{"url":"https://git.kernel.org/stable/c/c7ad910e987008e125eeff448892e86852173384"},{"url":"https://git.kernel.org/stable/c/86d54cf069fc5ae2e111c87933bebf6eb527978e"},{"url":"https://git.kernel.org/stable/c/2b2a903bee56d312539046d9defa8023eec94760"},{"url":"https://git.kernel.org/stable/c/47b079e2117a2ee52e21f8b72935900c702fc0b5"}],"title":"bpf: Fix use-after-free on mm_struct in bpf_find_vma()","x_generator":{"engine":"bippy-1.2.0"}}}}